Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3cw3-5vxw-g2h3

Опубликовано: 31 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 7.4
CVSS3: 7.3

Описание

OpenClaw: CLI Remote Onboarding Persists Unauthenticated Discovery Endpoint and Exfiltrates Gateway Credentials

Summary

Remote onboarding accepted discovered gateway endpoints without an explicit trust confirmation before persisting the remote URL and connection details.

Impact

A malicious or spoofed discovery endpoint could steer onboarding toward an attacker-controlled gateway and capture future gateway credentials or traffic.

Affected Component

src/commands/onboard-remote.ts

Fixed Versions

  • Affected: <= 2026.3.24
  • Patched: >= 2026.3.28
  • Latest stable 2026.3.28 contains the fix.

Fix

Fixed by commit d6affb17d8 (CLI: confirm discovered remote gateways before saving config).

Пакеты

Наименование

openclaw

npm
Затронутые версииВерсия исправления

<= 2026.3.24

2026.3.28

EPSS

Процентиль: 3%
0.00126
Низкий

7.4 High

CVSS4

7.3 High

CVSS3

Дефекты

CWE-287
CWE-862

Связанные уязвимости

CVSS3: 7.3
nvd
4 месяца назад

OpenClaw before 2026.3.28 contains an authentication bypass vulnerability in the remote onboarding component that persists unauthenticated discovery endpoints without explicit trust confirmation. Attackers can spoof discovery endpoints to redirect onboarding toward malicious gateways and capture gateway credentials or traffic.

EPSS

Процентиль: 3%
0.00126
Низкий

7.4 High

CVSS4

7.3 High

CVSS3

Дефекты

CWE-287
CWE-862