GHSA-7jm2-g593-4qrc: OpenClaw: Agent gateway config mutations could change protected operator settings
The agent-facing gateway config.patch / config.apply guard did not cover several operator-trusted settings, including sandbox policy, plugin enablement, gateway auth/TLS, hook routing, MCP server configuration, SSRF policy, and filesystem hardening. A prompt-injected model with access to the owner-only gateway tool could persist changes to those settings.
This is a model-to-operator guard bypass, not a remote unauthenticated gateway compromise. Severity is medium.
References
Code Behaviors & Features
Detect and mitigate GHSA-7jm2-g593-4qrc with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →