A paired node device could reconnect with spoofed platform/deviceFamily metadata and broaden node command policy eligibility because reconnect metadata was accepted from the client while these fields were not bound into the device-auth signature.
openclaw (npm)<= 2026.2.252026.2.252026.2.26In configurations where node command policy differs by platform, an attacker with an already paired node identity on the trusted network could spoof reconnect metadata and gain access to commands that should remain blocked for the originally paired platform.
v3 that signs normalized platform and deviceFamily.v3 first (fallback to v2 for compatibility), while pinning paired metadata server-side.7d8aeaaf06e2e616545d2c2cec7fa27f36b59b6apatched_versions is pre-set to the planned next release 2026.2.26; once that npm release is published, the advisory can be published without further field edits.
OpenClaw thanks @76embiid21 for reporting.
{
"cwe_ids": [
"CWE-290",
"CWE-863"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-03T00:40:12Z",
"nvd_published_at": "2026-03-19T22:16:34Z",
"severity": "HIGH"
}