Junglewise Threat Intelligence

OpenClaw TOCTOU race condition in node pairing reconnection

Severity: high · CVSS 7.6 · Published 2026-07-02

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, an AI assistant platform, contains a vulnerability where reconnecting nodes can bypass intended security restrictions. This could allow a connected device or service to gain more authority than originally granted by the administrator. If exploited, an attacker could potentially access sensitive data or perform unauthorized actions within the assistant's environment.

Technical details

A Time-of-check Time-of-use (TOCTOU) race condition (CWE-367) exists in OpenClaw's node pairing mechanism. In affected versions, a paired or reconnecting node session can mutate the pairing state during the reconnection process, leading to an incorrect approval scope decision. An attacker with low privileges can exploit this over the network to escalate the authority of a node beyond what was intended by the operator. The vulnerability is patched in version 2026.5.27.

Affected products

  • openclaw openclaw < 2026.5.27

Timeline

  • 2026-05-28: disclosed: Initial disclosure by reporter
  • 2026-05-28: patched: First stable patched version released
  • 2026-07-02: advisory: GitHub Advisory published

References

Related threats