Impact
OpenClaw versions prior to 2026.6.5 contain a flaw in the handling of HTTP Canvas responses, identified as CWE‑345, that allows callers with lower‑trust levels to forge requests that are treated as if they originated from trusted users. This can lead to the execution of actions that normally require stronger authorization, effectively enabling privilege escalation or the performance of privileged operations without proper authentication or authorization.
Affected Systems
The vulnerability affects all installations of OpenClaw running on node.js with a version earlier than 2026.6.5. These systems expose HTTP Canvas endpoints that can be accessed by lower‑trust callers. No mitigation is available for versions beyond the stated threshold without updating the software or enforcing additional controls on the problematic endpoints.
Risk and Exploitability
Based on the description, it is inferred that attackers need network access to submit crafted HTTP Canvas requests to the affected application. The overall severity is marked by a CVSS score of 5.1, indicating a medium risk. The EPSS score is less than 1 %, suggesting that the likelihood of exploitation within the next year is low, and the vulnerability is not listed in CISA’s KEV catalog. Attacks would then leverage the bypassed policy checks to perform actions that normally require higher authorization levels. The attack vector is network‑based and requires the ability to send HTTP requests to the affected endpoints.
OpenCVE Enrichment