GHSA-q99w-vh6v-q3v7

Suggest an improvement
Source
https://github.com/advisories/GHSA-q99w-vh6v-q3v7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-q99w-vh6v-q3v7/GHSA-q99w-vh6v-q3v7.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q99w-vh6v-q3v7
Aliases
  • CVE-2026-53843
Downstream
Published
2026-06-18T13:03:24Z
Modified
2026-06-18T13:16:05.229424188Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
OpenClaw: Pairing-scoped device session could restore revoked node token authority
Details

Summary

In affected releases, a surviving pairing-scoped session for a device could re-establish node token authority after that node token had been revoked. Revocation should require the device to lose that authority unless it is approved again through the normal pairing flow.

This issue affects token revocation and device-role containment. It does not allow unauthenticated device creation.

Affected configurations

This affects deployments where an already paired device keeps a same-device session with pairing-related scope after its node token is revoked.

Impact

A device that should have lost node WebSocket authority could regain it without renewed approval. That weakens revocation as an operator control and can keep node-level access alive longer than intended.

The impact is limited to devices that already had a legitimate pairing/session foothold.

Patched Versions

The first stable patched version is 2026.5.26.

Mitigations

Upgrade to openclaw@2026.5.26 or later. If a node token was revoked on an older version, restart the gateway and remove/re-pair the affected device to ensure no stale session remains active.

Database specific
{
    "nvd_published_at": null,
    "github_reviewed_at": "2026-06-18T13:03:24Z",
    "github_reviewed": true,
    "severity": "HIGH",
    "cwe_ids": [
        "CWE-284",
        "CWE-863"
    ]
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2026.5.26

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-q99w-vh6v-q3v7/GHSA-q99w-vh6v-q3v7.json"