CVE-2026-53843High· 8.8▾ TwilightOpenClaw: Pairing-scoped device session could restore revoked node token authority
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.3%
In affected releases, a surviving pairing-scoped session for a device could re-establish node token authority after that node token had been revoked. Revocation should require the device to lose that authority unless it is approved again through the normal pairing flow.
This issue affects token revocation and device-role containment. It does not allow unauthenticated device creation.
This affects deployments where an already paired device keeps a same-device session with pairing-related scope after its node token is revoked.
A device that should have lost node WebSocket authority could regain it without renewed approval. That weakens revocation as an operator control and can keep node-level access alive longer than intended.
The impact is limited to devices that already had a legitimate pairing/session foothold.
The first stable patched version is 2026.5.26.
Upgrade to [email protected] or later. If a node token was revoked on an older version, restart the gateway and remove/re-pair the affected device to ensure no stale session remains active.
openclaw < 2026.5.26Upgrade to a patched release:
openclaw 2026.5.26Connected by shared product, vendor, weakness, or advisory.
GHSA-wrmq-9fc4-gwwjHigh· 8.8Duplicate Advisory: Pairing-scoped device session could restore revoked node token authority
CVE-2026-53816High· 7.2OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance
GHSA-xww8-gqvh-92x9High· 8.0OpenClaw: Exec approval display truncation could hide the command being approved
GHSA-rggc-m335-3wvjHighOpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
CVE-2026-53817High· 8.0OpenClaw: Control UI locality spoofing could mint a durable admin device token
CVE-2026-53855High· 8.1OpenClaw: Shell positional parameters could weaken strict inline-eval checks