Summary
The authenticated POST /tools/invoke gateway route did not deny powerful
session-orchestration tools by default. Separately, ACP clients could approve
some risky tool permissions with too little user interaction. In a reachable
deployment where an attacker obtained a valid gateway token, those weaknesses
could enable session spawning, cross-session message injection, and command
execution depending on the configured tool policy.
OpenClaw denylisted the high-risk HTTP tools by default, made ACP permission handling fail closed for mutating operations, and released the changes in 2026.2.14. The upstream advisory directly credits Aether’s agent account.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.