Executive brief
OpenClaw is a user-controlled local AI assistant. When administrators rotate the shared gateway token for security purposes, existing WebSocket sessions authenticated with the old token are not disconnected. This allows an attacker with access to an old session to continue using the service after the token has been intentionally revoked, bypassing the administrator's security control.
Technical details
This is an insufficient session expiration vulnerability (CWE-613) in OpenClaw's WebSocket gateway authentication mechanism. When the shared gateway token is rotated, the system fails to invalidate or disconnect existing WebSocket sessions that were authenticated using the previous token. An attacker with an active WebSocket session can continue to send requests and interact with the local assistant even after the token has been rotated by the administrator. The vulnerability is scoped to OpenClaw's trust model as a user-controlled local assistant and does not assume a multi-tenant service boundary. The fix was verified in commit d7c3210cd6f5fdfdc1beff4c9541673e814354d5 and released in version 2026.4.8.
Affected products
- OpenClaw openclaw <= 2026.4.1
Timeline
- 2026-04-09: disclosed: Vulnerability published as GHSA-5h3f-885m-v22w
- 2026-04-08: patched: Fix available in version 2026.4.8