highVulnerability

GHSA-3cw3-5vxw-g2h3

## Summary Remote onboarding accepted discovered gateway endpoints without an explicit trust confirmation before persisting the remote URL and connection details. ## Impact A malicious or spoofed discovery endpoint could steer onboarding toward an attacker-controlled gateway and capture future gateway credentials or traffic. ## Affected Component `src/commands/onboard-remote.ts` ## Fixed Versions - Affected: `<= 2026.3.24` - Patched: `>= 2026.3.28` - Latest stable `2026.3.28` contains the fix. ## Fix Fixed by commit `d6affb17d8` (`CLI: confirm discovered remote gateways before saving config`).

Properties

ghsa_id
GHSA-3cw3-5vxw-g2h3
summary
OpenClaw: CLI Remote Onboarding Persists Unauthenticated Discovery Endpoint and Exfiltrates Gateway Credentials
severity
high
cve_id
GHSA-3cw3-5vxw-g2h3
is_ghsa_only
true
ghsa_published
2026-03-31T23:51:04Z
source_url
https://github.com/advisories/GHSA-3cw3-5vxw-g2h3
ghsa_updated
2026-03-31T23:51:04Z

Related Entities (4)

AFFECTS (1)

[Software]npm/OpenClaw

REPORTED_BY (1)

[Source]GitHub Advisory Database

HAS_WEAKNESS (2)

[Weakness]Missing Authorization
[Weakness]Improper Authentication

Explore deeper with Ninja Signal's threat intelligence graph