Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3qg8-hq7j-jj33

Опубликовано: 13 июн. 2026
Источник: github
Github: Прошло ревью
CVSS4: 7.4
CVSS3: 7.7

Описание

Duplicate Advisory: OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-rggc-m335-3wvj. This link is maintained to preserve external references.

Original Description

OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to forge trusted-proxy identity headers. Attackers with access to the proxy-facing Gateway port can supply forged identity headers to assume operator identity and potentially escalate privileges.

Пакеты

Наименование

openclaw

npm
Затронутые версииВерсия исправления

< 2026.5.18

2026.5.18

7.4 High

CVSS4

7.7 High

CVSS3

Дефекты

CWE-290

7.4 High

CVSS4

7.7 High

CVSS3

Дефекты

CWE-290