Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ GHSA-6x2m-hqfw-hvpj — openclaw

⚪ Unknown ✅ No Known Exploit CWE-285 OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

OpenClaw: Node exec approvals could be replayed across nodes

Summary

exec.approval requests for host=node were not explicitly bound to the target nodeId, so an approval intended for one node could be replayed for a different node under the same operator-controlled gateway fleet.

Impact

An operator approval for a system.run request could be reused across nodes if the request payload did not carry node identity through approval and execution checks.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Affected: <= 2026.2.22-2
  • Fixed: 2026.2.23 (released)

Mitigation

Upgrade to 2026.2.23 or later once published.

Fix Details

The fix requires and persists nodeId for host=node approval requests and rejects execution when the approving node binding does not match the invoking node.

Fix Commit(s)

  • 4a3f8438e527ac371a67fe7ac68a287f0dbe6063

Release Process Note

patched_versions is pre-set to the released version (2026.2.23). This advisory now reflects released fix version 2026.2.23.

OpenClaw thanks @tdjackey for reporting.

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. Rated impact: confidentiality none, integrity low, availability none.

Weakness class

GHSA-6x2m-hqfw-hvpj is classified as CWE-285: Improper Authorization. A request is carried out without confirming that the caller is permitted to perform it on that specific resource.

Affected software

GHSA-6x2m-hqfw-hvpj is recorded against 1 package.

  • openclaw

Timeline and source

Published on 2 March 2026 and last revised on 4 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

github.com (Web)
github.com (Web)
github.com (Package)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
CWE CWE-285
Public Exploit ✅ No
Source OSV
Published 2026-03-02
Updated 2026-08-20
Modified 2026-03-04
Fix URL N/A

Affected Packages

Software From version Fixed in
openclaw

Similar Threats

Free Vulnerability Check

Is your site affected by GHSA-6x2m-hqfw-hvpj?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against GHSA-6x2m-hqfw-hvpj and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.