#VU125237 Incorrect authorization in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to incorrect authorization in chat.send and persisted session mutation handling when processing the /verbose command. A remote user can send a write-scoped chat request using /verbose to disclose sensitive information.
The issue allows persistence of verbose output settings for later runs through a path that should be restricted to admin-only session changes.