{"id":"GHSA-wrmq-9fc4-gwwj","title":"Duplicate Advisory: Pairing-scoped device session could restore revoked node token authority","summary":"Duplicate Advisory: Pairing-scoped device session could restore revoked node token authority","severity":"high","cvss":8.8,"cwe":["CWE-613"],"vendor":"openclaw","product":"openclaw","ecosystem":"npm","affected":["openclaw < 2026.5.26"],"published":"2026-06-16","updated":"2026-06-18","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-wrmq-9fc4-gwwj","references":[{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-q99w-vh6v-q3v7"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53843"},{"url":"https://www.vulncheck.com/advisories/openclaw-node-token-revocation-bypass-via-pairing-scoped-device-session"},{"url":"https://github.com/advisories/GHSA-wrmq-9fc4-gwwj"}],"tags":["ghsa","npm"],"ingestedAt":"2026-06-29T14:31:47.655Z","slug":"GHSA-wrmq-9fc4-gwwj","body":"## Overview\n\n## Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of GHSA-q99w-vh6v-q3v7. This link is maintained to preserve external references.\n\n## Original Description\nOpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device session can re-establish node token authority after revocation. Attackers with a paired device can regain WebSocket node-level access without renewed approval, weakening revocation controls and maintaining unauthorized access longer than intended.\n\n## Affected packages\n\n- `openclaw < 2026.5.26`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}