PT-2026-27300 · Npm · Openclaw

Publicado

2026-03-13

·

Atualizado

2026-03-13

CVSS v3.1

8.4

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Summary

The built-in session status tool did not enforce the intended session-visibility boundary. A sandboxed subagent could supply another session's sessionKey and inspect or modify state outside its own sandbox scope.

Impact

This allowed a sandboxed child session to read parent or sibling session data and, in affected releases, update the target session's persisted model override.

Affected versions

openclaw <= 2026.3.8

Patch

Fixed in openclaw 2026.3.11 and included in later releases such as 2026.3.12. Session visibility checks now enforce the sandbox boundary before reading or mutating session state.

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-WCXR-59V9-RXR8

Produtos afetados

Openclaw