Опубликовано: 13 июн. 2026
Источник: github
Github: Прошло ревью
CVSS4: 7.4
CVSS3: 7.7
Описание
Duplicate Advisory: OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-rggc-m335-3wvj. This link is maintained to preserve external references.
Original Description
OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to forge trusted-proxy identity headers. Attackers with access to the proxy-facing Gateway port can supply forged identity headers to assume operator identity and potentially escalate privileges.
Пакеты
Наименование
openclaw
npm
Затронутые версииВерсия исправления
< 2026.5.18
2026.5.18
7.4 High
CVSS4
7.7 High
CVSS3
Дефекты
CWE-290
7.4 High
CVSS4
7.7 High
CVSS3
Дефекты
CWE-290