Skip to content

OpenClaw: Plugin subagent routes could bypass gateway authorization with synthetic admin scopes

Critical severity GitHub Reviewed Published Mar 12, 2026 in openclaw/openclaw • Updated Apr 6, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts