GHSA-jf6w-m8jw-jfxc: OpenClaw: Write-scoped callers could reach admin-only session reset logic through `agent`
In affected versions of openclaw, a gateway caller with operator.write could issue agent requests containing /new or /reset and reach the same reset path used by the admin-only sessions.reset RPC.
References
Code Behaviors & Features
Detect and mitigate GHSA-jf6w-m8jw-jfxc with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →