criticalVulnerability

GHSA-fqw4-mph7-2vr8

## Summary Gateway local shared-auth reconnect silently widens paired device scope from operator.read to operator.admin and reach node RCE ## Affected Packages / Versions - Package: `openclaw` - Affected versions: `<= 2026.3.24` - First patched version: `2026.3.25` - Latest published npm version at verification time: `2026.3.24` ## Details Silent local shared-auth reconnects could previously auto-approve `scope-upgrade` requests and widen a paired device from `operator.read` to `operator.admin`. Commit `81ebc7e0344fd19c85778e883bad45e2da972229` blocks silent reconnect scope upgrades so widened scopes require an explicit pairing approval instead of an implicit local reconnect path. Verified vulnerable on tag `v2026.3.24` and fixed on `main` by commit `81ebc7e0344fd19c85778e883bad45e2da972229`. ## Fix Commit(s) - `81ebc7e0344fd19c85778e883bad45e2da972229`

Properties

ghsa_id
GHSA-fqw4-mph7-2vr8
severity
critical
summary
OpenClaw: Silent privilege escalation via gateway shared-auth reconnect
cve_id
GHSA-fqw4-mph7-2vr8
is_ghsa_only
true
ghsa_published
2026-03-27T22:29:47Z
source_url
https://github.com/advisories/GHSA-fqw4-mph7-2vr8
ghsa_updated
2026-03-27T22:29:50Z

Related Entities (3)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (1)

[Weakness]Incorrect Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph