mediumVulnerability

GHSA-6x2m-hqfw-hvpj

## Summary `exec.approval` requests for `host=node` were not explicitly bound to the target `nodeId`, so an approval intended for one node could be replayed for a different node under the same operator-controlled gateway fleet. ## Impact An operator approval for a `system.run` request could be reused across nodes if the request payload did not carry node identity through approval and execution checks. ## Affected Packages / Versions - Package: `openclaw` (npm) - Affected: `<= 2026.2.22-2` - Fixed: `2026.2.23` (released) ## Mitigation Upgrade to `2026.2.23` or later once published. ## Fix Details The fix requires and persists `nodeId` for `host=node` approval requests and rejects execution when the approving node binding does not match the invoking node. ## Fix Commit(s) - 4a3f8438e527ac371a67fe7ac68a287f0dbe6063 ## Release Process Note `patched_versions` is pre-set to the released version (`2026.2.23`). This advisory now reflects released fix version `2026.2.23`. OpenClaw thanks @tdjackey for reporting.

Properties

ghsa_id
GHSA-6x2m-hqfw-hvpj
severity
medium
summary
OpenClaw: Node exec approvals could be replayed across nodes
cve_id
GHSA-6x2m-hqfw-hvpj
is_ghsa_only
true
ghsa_published
2026-03-02T22:29:45Z
source_url
https://github.com/advisories/GHSA-6x2m-hqfw-hvpj
ghsa_updated
2026-03-02T22:29:46Z

Related Entities (4)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (2)

[Weakness]Improper Authorization
[Weakness]Incorrect Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph