{"id":"CVE-2026-53816","title":"OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance","summary":"OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance","severity":"high","cvss":7.2,"cwe":["CWE-284","CWE-862","CWE-863"],"vendor":"openclaw","product":"openclaw","ecosystem":"npm","affected":["openclaw < 2026.5.18"],"patched":["openclaw 2026.5.18"],"published":"2026-07-02","updated":"2026-07-02","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-3c6j-hq33-3jv4","references":[{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-3c6j-hq33-3jv4"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53816"},{"url":"https://www.vulncheck.com/advisories/openclaw-exec-lifecycle-event-forgery-via-paired-node"},{"url":"https://github.com/advisories/GHSA-3c6j-hq33-3jv4"}],"tags":["ghsa","npm"],"epss":0.00342,"epssPercentile":0.27885,"ingestedAt":"2026-07-02T17:40:39.312Z","slug":"CVE-2026-53816","body":"## Overview\n\n### Summary\n\nOpenClaw nodes send lifecycle events back to the gateway. In affected releases, a paired node could send an exec lifecycle event that was accepted without enough provenance tying it to an authorized `system.run` request.\n\nThis issue affects the node event boundary. It does not allow an unauthenticated caller to reach the gateway; the attacker must already control a paired node connection.\n\n### Affected configurations\n\nThis affects deployments with a paired node where that node can send crafted `node.event` messages to the gateway and the target agent/session can process exec lifecycle events.\n\n### Impact\n\nA malicious or compromised paired node could make the gateway treat attacker-supplied event data as an exec lifecycle result. In the vulnerable flow, that could steer the target session into an exec-event path that exposed capabilities the reduced node surface should not have provided.\n\nThe issue is a missing provenance check for node-originated lifecycle events.\n\n### Patched Versions\n\nThe first stable patched version is `2026.5.18`.\n\n### Mitigations\n\nUpgrade to `openclaw@2026.5.18` or later. Pair nodes only from trusted environments, and remove/re-pair nodes that may have been compromised.\n\n## Affected packages\n\n- `openclaw < 2026.5.18`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `openclaw 2026.5.18`","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":39.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}