Gateway device.token.rotate does not terminate active WebSocket sessions after credential rotation
openclaw (npm)2026.3.31<=2026.3.28>= 2026.3.31v2026.3.3191f7a6b0fd67b703897e6e307762d471ca09333d — 2026-03-31T09:05:34+09:002026.3.31.Thanks @zsxsoft for reporting.
{
"github_reviewed": true,
"severity": "LOW",
"github_reviewed_at": "2026-04-03T03:11:33Z",
"nvd_published_at": null,
"cwe_ids": [
"CWE-613"
]
}