Executive brief
OpenClaw, an AI assistant platform, contains a vulnerability in its device pairing process. An attacker with access to a temporary setup token could potentially reuse it to request broader access permissions than originally intended before the pairing is finalized. This could lead to an unauthorized expansion of access rights within the system, depending on how the administrator has configured the gateway.
Technical details
A vulnerability in OpenClaw (npm package) allows for bootstrap token replay during the pairing process. In affected versions up to 2026.5.10-beta.2, a caller who possesses a pending bootstrap token can reuse that token to modify and broaden the requested scope set before the pairing is officially approved by an operator. This is classified as Improper Privilege Management (CWE-269). The attack requires network reachability and specific timing (before approval), with a CVSS complexity of High. The issue is resolved in version 2026.5.12.
Affected products
- openclaw openclaw <= 2026.5.10-beta.2
Timeline
- 2026-05-28: disclosed: Initial disclosure by reporter
- 2026-06-18: advisory: GitHub Advisory published
- 2026-05-12: patched: First stable patched version released