UNKNOWN npm
OpenClaw: Gateway HTTP /sessions/:sessionKey/kill Reaches Admin Kill Path Without Caller Scope Binding
GHSA-9p93-7j67-5pc2 · CVE-2026-34512
Published · Modified
Description
Summary
Gateway HTTP /sessions/:sessionKey/kill Reaches Admin Kill Path Without Caller Scope Binding.
Details
The HTTP route previously treated any bearer-authenticated request as admin-eligible and could call without binding the action to requester ownership or caller-granted operator scopes. The flaw removes the bearer-token admin fallback and keeps remote session kills on the local-admin or requester-owned path only.
Ready to move
Start Securing
Free, no credit card | First findings in minutes