GHSA-qjpc-qf9m-xwmr

Suggest an improvement
Source
https://github.com/advisories/GHSA-qjpc-qf9m-xwmr
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-qjpc-qf9m-xwmr/GHSA-qjpc-qf9m-xwmr.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qjpc-qf9m-xwmr
Aliases
Downstream
Published
2026-07-02T16:43:53Z
Modified
2026-07-08T08:27:08Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing
Details

Summary

In trusted-proxy Control UI mode, OpenClaw accepted a WebSocket client's declared operator scopes before those scopes were bound to a server-approved pairing or trusted-proxy authorization baseline.

This issue affects trusted-proxy Control UI deployments. It does not apply to shared-secret Control UI sessions, which are treated as trusted operator sessions by design.

Affected configurations

This affects deployments using gateway.auth.mode: "trusted-proxy" for Control UI access where a restricted trusted-proxy user could open a Control UI WebSocket and present a fresh, unpaired device identity with elevated requested scopes.

Impact

An unpaired or restricted trusted-proxy Control UI client could obtain cached operator.admin authority on its live WebSocket connection. That authority could then be used for admin-gated Gateway RPCs until the connection was closed or revalidated.

Patched Versions

The first stable patched version is 2026.5.18.

Mitigations

Upgrade to openclaw@2026.5.18 or later. Before upgrading, restrict trusted-proxy Control UI access to users who should have the scopes they can request, and restart the gateway after changing trusted-proxy authorization policy.

Database specific
{
    "cwe_ids":  [
        "CWE-862",
        "CWE-863"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-07-02T16:43:53Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2026.5.18

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-qjpc-qf9m-xwmr/GHSA-qjpc-qf9m-xwmr.json"