Incomplete scope-clearing fix allows operator.admin escalation via trusted-proxy auth mode
openclaw (npm)2026.3.31<=2026.3.28>= 2026.3.31v2026.3.318b88b927cb0747ad24d95b07d35682bf85dc5b0e — 2026-03-30T14:19:00+01:00OpenClaw thanks @north-echo for reporting.
2026.3.31Exploitability
AV:NAC:LAT:NPR:LUI:NVulnerable System
VC:HVI:HVA:NSubsequent System
SC:NSI:NSA:N8.6/CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N