OpenClaw's ACP child sessions inherit subagent security envelope constraints
Moderate severity
GitHub Reviewed
Published
Apr 23, 2026
in
openclaw/openclaw
•
Updated May 29, 2026
Description
Published to the GitHub Advisory Database
May 4, 2026
Reviewed
May 4, 2026
Last updated
May 29, 2026
Summary
ACP child sessions inherit subagent security envelope constraints.
Affected Packages / Versions
Impact
A restricted subagent spawning an ACP child session could fail to carry forward subagent-only constraints such as depth, child-count limits, control scope, or target-agent restrictions.
Fix
ACP spawn now resolves and persists child subagent envelope fields, enforces maximum depth and active-child caps, and applies the inherited control scope to child ACP sessions.
Fix Commit(s)
Verification
OpenClaw thanks @zsxsoft, @qclawer, and @KeenSecurityLab for reporting.
References