GHSA-f6h3-846h-2r8w: OpenClaw's elevated allowFrom accepted broader identity signals than specified within sender-scoped authorization
In certain elevated-mode configurations, tools.elevated.allowFrom accepted broader identity signals than intended. The fix tightens matching to sender-scoped identity by default and makes mutable metadata matching explicit.
References
Code Behaviors & Features
Detect and mitigate GHSA-f6h3-846h-2r8w with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →