Encoded alternate-path requests could bypass plugin route auth checks for /api/channels/* due to canonicalization depth mismatch in vulnerable builds.
openclaw (npm)2026.3.1<= 2026.3.12026.3.2 (patched_versions: >= 2026.3.2)In affected versions, plugin auth-path classification and route-path canonicalization could diverge for deeply encoded slash variants (for example multi-encoded %2f). That mismatch allowed alternate encoded paths to evade protected-prefix auth checks while still resolving to /api/channels/... in plugin route handling.
The fix set hardens this class of issue by:
Deployments exposing plugin HTTP routes and relying on gateway auth for /api/channels/* protection.
93b07240257919f770d1e263e1f22753937b80ea2fd8264ab03bd178e62a5f0c50d1c8556c17f12dd74bc257d8432f17e50b23ae713d7e0623a1fe0f7a7eee920a176a0043398c6b37bf4cc6eb983eeb{
"cwe_ids": [
"CWE-288"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-03T21:25:52Z",
"nvd_published_at": "2026-03-19T22:16:32Z",
"severity": "HIGH"
}