---
id: GHSA-hc4w-hm59-9w88
title: >-
  Duplicate Advisory: Empty-scope device re-pairing could confuse caller scope
  containment
summary: >-
  Duplicate Advisory: Empty-scope device re-pairing could confuse caller scope
  containment
severity: low
cvss: 5.4
cwe:
  - CWE-636
vendor: openclaw
product: openclaw
ecosystem: npm
affected:
  - openclaw <= 2026.4.24
published: '2026-06-16'
updated: '2026-06-18'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-hc4w-hm59-9w88'
references:
  - url: >-
      https://github.com/openclaw/openclaw/security/advisories/GHSA-8mg9-j9cf-54cj
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53852'
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-scope-bypass-via-empty-scope-device-re-pairing
  - url: 'https://github.com/advisories/GHSA-hc4w-hm59-9w88'
tags:
  - ghsa
  - npm
ingestedAt: '2026-06-29T14:31:47.493Z'
---

## Overview

## Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-8mg9-j9cf-54cj. This link is maintained to preserve external references.

## Original Description
OpenClaw before 2026.4.25 contains a scope containment bypass vulnerability in device re-pairing that allows authenticated operators to restore broader scopes than intended by submitting empty-scope re-pairing requests. Attackers can exploit this by sending re-pairing requests with empty scope sets to skip containment guards and retain unauthorized device access.

## Affected packages

- `openclaw <= 2026.4.24`

## Remediation

Refer to the advisory for the patched release.
