#VU125146 Incorrect authorization in OpenClaw - CVE-2026-32919
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a local user to reset targeted conversation state.
The vulnerability exists due to incorrect authorization in the agent slash-command path when processing agent requests containing /new or /reset. A local user can send a specially crafted agent request to reset targeted conversation state.
The issue crosses the documented boundary between write-scoped messaging and admin-only session mutation.