OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that allows low-privilege operators to approve nodes with broader scopes. Attackers…
High CVSS 8.1
Summary
OpenClaw before 2026.3.28 contains an insufficient scope validation vulnerability in the node pairing approval path that allows low-privilege operators to approve nodes with broader scopes. Attackers can exploit missing callerScopes validation in node-pairing.ts to extend privileges onto paired nodes beyond their authorization level.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/openclaw/openclaw/commit/4d7cc6bb4fac68b5a5fadd1c5a23168281221f34 Patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-2x4x-cc5g-qmmg Vendor Advisory
- https://www.vulncheck.com/advisories/openclaw-insufficient-scope-validation-in-node-pair-approve Third Party Advisory
Timeline
- nvd_ingest NVD