GHSA-wrmq-9fc4-gwwjHigh· 8.8▾ TwilightDuplicate Advisory: Pairing-scoped device session could restore revoked node token authority
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-q99w-vh6v-q3v7. This link is maintained to preserve external references.
OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device session can re-establish node token authority after revocation. Attackers with a paired device can regain WebSocket node-level access without renewed approval, weakening revocation controls and maintaining unauthorized access longer than intended.
openclaw < 2026.5.26Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53843High· 8.8OpenClaw: Pairing-scoped device session could restore revoked node token authority
GHSA-275c-xpvc-jgfwMediumOpenClaw: Slack and Zalo webhook secrets could remain active after secrets.reload
GHSA-4m3v-q747-pc6hMediumOpenClaw: Mattermost slash token revocation could lag until monitor refresh
CVE-2026-34503High· 8.1OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked
GHSA-c29c-2q9c-pc86HighOpenClaw: Slack allowFrom could bind to mutable display names
GHSA-qjpc-qf9m-xwmrHigh· 8.8OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing