{"id":"GHSA-qjpc-qf9m-xwmr","title":"OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing","summary":"OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing","severity":"high","cvss":8.8,"cwe":["CWE-862","CWE-863"],"vendor":"openclaw","product":"openclaw","ecosystem":"npm","affected":["openclaw < 2026.5.18"],"patched":["openclaw 2026.5.18"],"published":"2026-07-02","updated":"2026-07-02","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-qjpc-qf9m-xwmr","references":[{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-qjpc-qf9m-xwmr"},{"url":"https://github.com/advisories/GHSA-qjpc-qf9m-xwmr"}],"tags":["ghsa","npm"],"ingestedAt":"2026-07-02T17:40:39.516Z","slug":"GHSA-qjpc-qf9m-xwmr","body":"## Overview\n\n### Summary\n\nIn trusted-proxy Control UI mode, OpenClaw accepted a WebSocket client's declared operator scopes before those scopes were bound to a server-approved pairing or trusted-proxy authorization baseline.\n\nThis issue affects trusted-proxy Control UI deployments. It does not apply to shared-secret Control UI sessions, which are treated as trusted operator sessions by design.\n\n### Affected configurations\n\nThis affects deployments using `gateway.auth.mode: \"trusted-proxy\"` for Control UI access where a restricted trusted-proxy user could open a Control UI WebSocket and present a fresh, unpaired device identity with elevated requested scopes.\n\n### Impact\n\nAn unpaired or restricted trusted-proxy Control UI client could obtain cached `operator.admin` authority on its live WebSocket connection. That authority could then be used for admin-gated Gateway RPCs until the connection was closed or revalidated.\n\n### Patched Versions\n\nThe first stable patched version is `2026.5.18`.\n\n### Mitigations\n\nUpgrade to `openclaw@2026.5.18` or later. Before upgrading, restrict trusted-proxy Control UI access to users who should have the scopes they can request, and restart the gateway after changing trusted-proxy authorization policy.\n\n## Affected packages\n\n- `openclaw < 2026.5.18`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `openclaw 2026.5.18`","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}