GHSA-xr4f-mjxj-w6w5High· 8.3▾ TwilightOpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The bundled device-pair plugin exposed /pair on normal chat command surfaces. In affected releases, authorized non-owner chat senders could issue device-pairing bootstrap codes without having owner, admin, or pairing scope.
This issue does not affect unauthenticated users. The caller must already be allowed to send commands to the agent through a configured chat channel.
This affects deployments where the bundled device-pair plugin is enabled and a non-owner sender is authorized to use normal chat commands, such as in a configured Telegram, Discord, or Slack agent.
A non-owner authorized sender could create a setup code and use it before expiry to enroll a device with operator/node capabilities. That device would then retain persistent credentials until removed.
The first stable patched version is 2026.5.4.
Upgrade to [email protected] or later. Review paired devices and remove any unexpected entries. In shared chat channels, keep command access limited to users who should be allowed to manage device pairing.
openclaw < 2026.5.4Upgrade to a patched release:
openclaw 2026.5.4Connected by shared product, vendor, weakness, or advisory.
GHSA-qjpc-qf9m-xwmrHigh· 8.8OpenClaw: Trusted-proxy Control UI WebSocket accepted client-declared scopes before pairing
GHSA-w4v6-g3wm-w36cCriticalOpenClaw: QQBot admin commands could skip DM-only and allowFrom policy
GHSA-77pv-3w4q-vrj5MediumOpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks
CVE-2026-53809Medium· 3.8OpenClaw: Embedded runner policy could be confused by provider aliases
CVE-2026-53816High· 7.2OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance
GHSA-w5ww-7chg-mxcqHighOpenClaw: Telegram interactive callbacks could skip commands.allowFrom