GHSA-8jhh-jcqg-mj5p: OpenClaw: Channel commands could bypass account-scoped `configWrites` restrictions
In affected versions of openclaw, channel-initiated config mutations were authorized against the originating account’s configWrites policy but did not consistently re-check the targeted account scope. An authorized sender on one account could mutate protected sibling-account configuration when the target account had configWrites: false.
References
Code Behaviors & Features
Detect and mitigate GHSA-8jhh-jcqg-mj5p with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →