Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xrq9-jm7v-g9h7

Опубликовано: 25 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 2.3

Описание

OpenClaw: Paired-device pairing actions were not limited to the caller device

Affected Packages / Versions

  • Package: openclaw (npm)
  • Affected versions: < 2026.4.20
  • Patched version: 2026.4.20

Impact

A paired device session with limited pairing scope could enumerate global pairing state and act on pairing requests that belonged to another device within the same gateway scope ceiling.

This is a same-gateway paired-device authorization bug, not a remote unauthenticated issue. Severity is low.

Fix

Pairing management actions are now limited to the caller device, so non-admin paired-device sessions cannot approve or operate on unrelated pending device requests.

Fix commit:

  • 5a12f30441d5b0b151f550daa2c5c9e8db61e2e6

Release

Fixed in OpenClaw 2026.4.20.

Пакеты

Наименование

openclaw

npm
Затронутые версииВерсия исправления

< 2026.4.20

2026.4.20

2.3 Low

CVSS4

Дефекты

CWE-284
CWE-863

2.3 Low

CVSS4

Дефекты

CWE-284
CWE-863