GHSA-jr6x-2q95-fh2g: OpenClaw's authorization mismatch allowed write-scope agent runs to reach owner-only tools
An authorization mismatch allowed authenticated callers with operator.write access to invoke owner-only tool surfaces (gateway, cron) through agent runs in scoped-token deployments.
References
Code Behaviors & Features
Detect and mitigate GHSA-jr6x-2q95-fh2g with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →