OpenClaw leaf subagents can bypass controlScope restrictions to send messages to child sessions
Moderate severity
GitHub Reviewed
Published
Mar 24, 2026
in
openclaw/openclaw
•
Updated Apr 10, 2026
Description
Published to the GitHub Advisory Database
Mar 26, 2026
Reviewed
Mar 26, 2026
Published by the National Vulnerability Database
Apr 10, 2026
Last updated
Apr 10, 2026
Summary
Leaf subagents could still use the send action to message controlled child sessions even when their controlScope was narrower than children.
Affected Packages / Versions
openclaw(npm)v2026.3.23-2(630f1479c44f78484dfa21bb407cbe6f171dac87)2026.3.23-2Fix Commit(s)
7679eb375294941b02214c234aff3948796969d0Release Status
The fix shipped in
v2026.3.22and remains present inv2026.3.23andv2026.3.23-2.Code-Level Confirmation
OpenClaw thanks @space08 for reporting.
References