OpenClaw before 2026.3.22 fails to enforce controlScope restrictions on the send action, allowing leaf subagents to message controlled child sessions beyond their authorized scope. Attackers can exploit this by using the send action to communicate with child sessions without proper scope validation, bypassing intended access control restrictions.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-x2cm-hg9c-mf5w | OpenClaw leaf subagents can bypass controlScope restrictions to send messages to child sessions |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 10 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw before 2026.3.22 fails to enforce controlScope restrictions on the send action, allowing leaf subagents to message controlled child sessions beyond their authorized scope. Attackers can exploit this by using the send action to communicate with child sessions without proper scope validation, bypassing intended access control restrictions. | |
| Title | OpenClaw < 2026.3.22 - Missing controlScope Enforcement in Send Action | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-10T18:24:24.250Z
Reserved: 2026-04-04T12:31:57.498Z
Link: CVE-2026-35662
No data.
Status : Received
Published: 2026-04-10T17:17:07.867
Modified: 2026-04-10T17:17:07.867
Link: CVE-2026-35662
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA