No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-x2cm-hg9c-mf5w | OpenClaw leaf subagents can bypass controlScope restrictions to send messages to child sessions |
Fri, 10 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw before 2026.3.22 fails to enforce controlScope restrictions on the send action, allowing leaf subagents to message controlled child sessions beyond their authorized scope. Attackers can exploit this by using the send action to communicate with child sessions without proper scope validation, bypassing intended access control restrictions. | |
| Title | OpenClaw < 2026.3.22 - Missing controlScope Enforcement in Send Action | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-10T18:24:24.250Z
Reserved: 2026-04-04T12:31:57.498Z
Link: CVE-2026-35662
Updated: 2026-04-10T18:24:16.349Z
Status : Received
Published: 2026-04-10T17:17:07.867
Modified: 2026-04-10T17:17:07.867
Link: CVE-2026-35662
No data.
OpenCVE Enrichment
No data.
Github GHSA