GHSA-chr9-m4q2-76hw

Suggest an improvement
Source
https://github.com/advisories/GHSA-chr9-m4q2-76hw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-chr9-m4q2-76hw/GHSA-chr9-m4q2-76hw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-chr9-m4q2-76hw
Aliases
Published
2026-07-02T16:04:35Z
Modified
2026-07-02T16:26:33Z
Severity
  • 8.0 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenClaw: Control UI locality spoofing could mint a durable admin device token
Details

Summary

In affected LAN/shared-token Control UI deployments, a caller could spoof locality information used during Control UI pairing and obtain a durable admin-capable device token.

This issue is limited to deployments where the caller already has the network/authentication foothold needed to reach the Control UI pairing path. It is not an unauthenticated internet exposure issue.

Affected configurations

This affects configurations such as LAN-bound gateways or shared-token Control UI access where locality signals were accepted as sufficient for pairing decisions.

Impact

A temporary or shared Control UI access path could be turned into a persistent admin device token. That token could remain useful after the shared gateway token was rotated, unless the paired device was removed.

The issue is a pairing/locality validation problem: locality-derived trust was stronger than it should have been.

Patched Versions

The first stable patched version is 2026.5.22.

Mitigations

Upgrade to openclaw@2026.5.22 or later. For older deployments, remove unexpected paired devices and avoid exposing Control UI pairing paths on networks with untrusted clients.

Database specific
{
    "cwe_ids":  [
        "CWE-284",
        "CWE-287",
        "CWE-290",
        "CWE-863"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-02T16:04:35Z",
    "nvd_published_at":  "2026-06-11T21:16:23Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2026.5.22

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-chr9-m4q2-76hw/GHSA-chr9-m4q2-76hw.json"