@openclaw/diagnostics-prometheus@2026.5.20

OpenClaw diagnostics Prometheus exporter for runtime metrics.

Direct Vulnerabilities

Known vulnerabilities in the @openclaw/diagnostics-prometheus package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Missing Authorization

@openclaw/diagnostics-prometheus is an OpenClaw diagnostics Prometheus exporter for runtime metrics.

Affected versions of this package are vulnerable to Missing Authorization via the authenticated metrics endpoint, which does not enforce the operator.read scope. An authenticated caller whose effective role lacks read access can retrieve the diagnostics document, disclosing operational metrics to an identity intentionally limited below read access. Ordinary read methods correctly reject the same identity, but the Prometheus endpoint bypasses this scope check entirely.

Note: This is only exploitable in deployments using an identity-bearing Gateway authentication mode such as trusted-proxy. Shared-secret Gateway callers already hold the full operator scope and are not affected.

How to fix Missing Authorization?

Upgrade @openclaw/diagnostics-prometheus to version 2026.9.3 or higher.

<2026.9.3