Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xj9w-5r6q-x6v4

Опубликовано: 03 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 7.7
CVSS3: 8.8

Описание

OpenClaw: Device-Paired Node Skips Node Scope Gate → Host RCE.md

Summary

Device-Paired Node Skips Node Scope Gate → Host RCE.md

Current Maintainer Triage

  • Status: open
  • Normalized severity: high
  • Assessment: Real in shipped v2026.3.28 because a merely device-paired node could expose node commands without node pairing, but high is sufficient given the pairing/setup prerequisites.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Latest published npm version: 2026.3.31
  • Vulnerable version range: <=2026.3.28
  • Patched versions: >= 2026.3.31
  • First stable tag containing the fix: v2026.3.31

Fix Commit(s)

  • 3886b65ef21d02808c1a106fa1f9f69e22f71c32 — 2026-03-30T17:29:28+01:00

OpenClaw thanks @AntAISecurityLab for reporting.

Пакеты

Наименование

openclaw

npm
Затронутые версииВерсия исправления

<= 2026.3.28

2026.3.31

EPSS

Процентиль: 43%
0.00544
Низкий

7.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-862
CWE-863

Связанные уязвимости

CVSS3: 8.8
nvd
4 месяца назад

OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node scope gate authentication mechanism. Attackers with device pairing credentials can execute arbitrary node commands on the host system without proper node pairing validation.

EPSS

Процентиль: 43%
0.00544
Низкий

7.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-862
CWE-863