UNKNOWN npm

OpenClaw: Gateway HTTP /sessions/:sessionKey/kill Reaches Admin Kill Path Without Caller Scope Binding

GHSA-9p93-7j67-5pc2 · CVE-2026-34512

Published · Modified

Description

Summary

Gateway HTTP /sessions/:sessionKey/kill Reaches Admin Kill Path Without Caller Scope Binding.

Details

The HTTP route previously treated any bearer-authenticated request as admin-eligible and could call without binding the action to requester ownership or caller-granted operator scopes. The flaw removes the bearer-token admin fallback and keeps remote session kills on the local-admin or requester-owned path only.

Ready to move

Start Securing

Free, no credit card | First findings in minutes