Missing Authorization Affecting @openclaw/diagnostics-prometheus package, versions <2026.9.3


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.25% (15th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Missing Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-OPENCLAWDIAGNOSTICSPROMETHEUS-20186831
  • published28 Sept 2026
  • disclosed26 Sept 2026
  • creditUnknown

Introduced: 26 Sep 2026

NewCVE-2026-100525  (opens in a new tab)
CWE-862  (opens in a new tab)

How to fix?

Upgrade @openclaw/diagnostics-prometheus to version 2026.9.3 or higher.

Overview

@openclaw/diagnostics-prometheus is an OpenClaw diagnostics Prometheus exporter for runtime metrics.

Affected versions of this package are vulnerable to Missing Authorization via the authenticated metrics endpoint, which does not enforce the operator.read scope. An authenticated caller whose effective role lacks read access can retrieve the diagnostics document, disclosing operational metrics to an identity intentionally limited below read access. Ordinary read methods correctly reject the same identity, but the Prometheus endpoint bypasses this scope check entirely.

Note: This is only exploitable in deployments using an identity-bearing Gateway authentication mode such as trusted-proxy. Shared-secret Gateway callers already hold the full operator scope and are not affected.

Workaround

Disable the Prometheus endpoint, or ensure every identity that can reach it is intended to hold the operator.read scope.

References

CVSS Base Scores

version 4.0
version 3.1