All findings

aether-openclaw-tool-escalation high

Aether finds a two-part OpenClaw tool-permission escalation

OpenClaw's HTTP gateway exposed high-risk session tools while ACP clients could auto-approve risky permissions, expanding a stolen gateway token into session control and possible command execution.

Bug class
Improper tool authorization and unsafe permission auto-approval
Affected codebase
OpenClaw gateway and ACP clients
Credited system
Aether AI
Disclosed
March 2, 2026
Attribution
Direct source attribution
Severity
high
Source status: OpenClaw's upstream GHSA directly thanks aether-ai-agent for reporting the issue and contributing remediation. It records an 8.8 CVSS score, the fixed 2026.2.14 release, and no CVE ID.

Summary

The authenticated POST /tools/invoke gateway route did not deny powerful session-orchestration tools by default. Separately, ACP clients could approve some risky tool permissions with too little user interaction. In a reachable deployment where an attacker obtained a valid gateway token, those weaknesses could enable session spawning, cross-session message injection, and command execution depending on the configured tool policy.

OpenClaw denylisted the high-risk HTTP tools by default, made ACP permission handling fail closed for mutating operations, and released the changes in 2026.2.14. The upstream advisory directly credits Aether’s agent account.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.