Summary
Gateway Plugin HTTP auth: "gateway" Mints operator.admin Runtime Scope
Affected Packages / Versions
- Package:
openclaw
- Affected versions:
<= 2026.3.24
- First patched version:
2026.3.25
- Latest published npm version at verification time:
2026.3.24
Details
Gateway-authenticated plugin HTTP routes previously created a runtime scope set that included operator.admin regardless of caller-granted scopes. Commit ec2dbcff9afd8a52e00de054b506c91726d9fbbe keeps plugin HTTP runtime scopes least-privileged and preserves caller scope boundaries.
Verified vulnerable on tag v2026.3.24 and fixed on main by commit ec2dbcff9afd8a52e00de054b506c91726d9fbbe.
Fix Commit(s)
ec2dbcff9afd8a52e00de054b506c91726d9fbbe
References
Summary
Gateway Plugin HTTP auth: "gateway" Mints operator.admin Runtime Scope
Affected Packages / Versions
openclaw<= 2026.3.242026.3.252026.3.24Details
Gateway-authenticated plugin HTTP routes previously created a runtime scope set that included
operator.adminregardless of caller-granted scopes. Commitec2dbcff9afd8a52e00de054b506c91726d9fbbekeeps plugin HTTP runtime scopes least-privileged and preserves caller scope boundaries.Verified vulnerable on tag
v2026.3.24and fixed onmainby commitec2dbcff9afd8a52e00de054b506c91726d9fbbe.Fix Commit(s)
ec2dbcff9afd8a52e00de054b506c91726d9fbbeReferences