OSV 1.4.0 · github-reviewed · 修改于 2026-07-03 00:05
发布时间
2026-07-03 00:05
GitHub 审查时间
2026-07-03 00:05
NVD 发布时间
2026-06-12 05:16
源文件
advisories/github-reviewed/2026/07/GHSA-6fvr-66p3-3qj4/GHSA-6fvr-66p3-3qj4.json
OpenClaw hook ingress can start automated agent runs using a configured hook token. In affected releases, a hook-triggered run could select a bundled CLI backend that received owner-scoped MCP loopback authority instead of a scope appropriate for hook ingress.
This issue affects the boundary between hook-token automation and owner-only MCP tools. It does not affect deployments with hooks disabled.
This affects deployments where hooks are enabled, /hooks/agent is reachable with a valid hook token, and a bundled CLI backend can be selected for the hook-triggered run.
A caller with the hook token could cause the spawned CLI runtime to see or call MCP tools that should have been owner-only. The practical impact depends on which MCP tools are available; the reported proof used persistent cron state as a representative owner-only action.
The first stable patched version is 2026.5.20.
Fixed in the 2026.5.20 stable release.
Upgrade to [email protected] or later. Keep hook tokens secret, restrict network access to hook endpoints, and disable hooks when they are not needed.