Executive brief
OpenClaw is an AI automation platform that allows devices to pair and communicate through setup codes. A vulnerability in pairing setup codes caused them to embed long-lived shared gateway credentials directly in the setup payload, rather than using short-lived bootstrap tokens. An attacker who obtained a setup code from chat history, logs, screenshots, or QR code copies could extract and reuse the shared credential indefinitely, potentially gaining unauthorized access to the gateway outside the intended one-time pairing flow.
Technical details
The vulnerability is an information disclosure issue (CWE-532) in OpenClaw's pairing mechanism. The /pair endpoint and openclaw qr command embedded the configured shared gateway token or password directly in the setup payload instead of using short-lived bootstrap tokens valid only for initial device bootstrap. An attacker with network access to a leaked or intercepted setup code could recover the long-lived shared gateway credential and replay it for unauthorized access. The vulnerability affects all versions of OpenClaw up to and including 2026.3.11. A patch is available in version 2026.3.12, which generates short-lived bootstrap tokens instead and is available in the npm package repository. Organizations should update to 2026.3.12 or later and rotate any previously exposed shared gateway credentials if setup codes may have been leaked.
Affected products
- OpenClaw OpenClaw <= 2026.3.11
Timeline
- 2026-03-13: disclosed
- 2026-03-12: patched: Fixed in version 2026.3.12