Executive brief
OpenClaw is a Node.js-based orchestration and automation platform. A vulnerability allows attackers with device-pairing credentials to bypass authentication controls and execute arbitrary commands on the host system, potentially compromising the entire infrastructure that depends on the platform.
Technical details
The vulnerability is an authentication bypass (CWE-862) in OpenClaw's node scope gate mechanism. A device-paired node can skip required scope validation and execute arbitrary node commands on the host without proper pairing verification. The attack requires valid device-pairing credentials (authentication prerequisite) but then allows network-accessible host RCE. The vulnerability affects all versions up to 2026.3.28; a fix was released in version 2026.3.31 (commit 3886b65ef21d02808c1a106fa1f9f69e22f71c32).
Affected products
- OpenClaw openclaw <=2026.3.28
Timeline
- 2026-03-31: disclosed
- 2026-03-31: patched: Fix released in version 2026.3.31
- 2026-04-24: advisory: GHSA-7vq9-42cc-33j4 published