Openclaw cli: OpenClaw: Gateway HTTP Session History Route Bypasses Operator Read Scope (CVE-2026-35657)
Description
The OpenClaw CLI has a vulnerability in its HTTP /sessions/:sessionKey/history route that allows bypassing the operator read scope check. This route authenticated bearer tokens but did not enforce the operator.read permission, unlike the WebSocket chat.history route. This flaw was fixed in version 2026.3.25 by requiring operator scopes and rejecting unauthorized history reads.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-35657 describes a security flaw in the OpenClaw CLI package versions up to 2026.3.24 where the HTTP route /sessions/:sessionKey/history authenticated bearer tokens but bypassed the operator.read scope check. This inconsistency allowed unauthorized access to session history data via HTTP. The issue was resolved in commit 1c45123231516fa50f8cf8522ba5ff2fb2ca7aea, which enforces operator scope declarations and rejects requests lacking operator.read permission. The vulnerability was verified on version 2026.3.24 and fixed in version 2026.3.25.
Potential Impact
Unauthorized users with bearer tokens but without the operator.read scope could access session history data via the HTTP route, potentially exposing sensitive session information. The vulnerability does not require user interaction or elevated privileges beyond bearer token possession. No known exploits in the wild have been reported.
Mitigation Recommendations
A patch is available and was introduced in version 2026.3.25. Users should upgrade to version 2026.3.25 or later to ensure the operator.read scope check is enforced on the HTTP session history route. No additional mitigation is required beyond applying this official fix.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-openclaw-cli-CVE-2026-35657
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 4.0
Threat ID: 6ac245ab12601ec6a3166293
Added to database: 10/04/2026, 12:25:15 UTC
Last enriched: 10/04/2026, 12:54:03 UTC
Last updated: 10/04/2026, 16:08:37 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.