mediumCVSS 5.5Vulnerability

GHSA-gw2c-6hcg-5g52

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-mpc8-jxjh-qpgh. This link is maintained to preserve external references. ## Original Description OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows authenticated callers to execute the command without proper authorization checks. Attackers can trigger the focus command to change focus state outside intended caller authority, potentially enabling unauthorized operations depending on gateway configuration and input trust levels.

Properties

ghsa_id
GHSA-gw2c-6hcg-5g52
severity
medium
summary
Duplicate Advisory: Focus command could miss controlScope enforcement
cvss_score
5.5
cve_id
GHSA-gw2c-6hcg-5g52
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
is_ghsa_only
true
ghsa_published
2026-06-16T21:31:58Z
source_url
https://github.com/advisories/GHSA-gw2c-6hcg-5g52
ghsa_updated
2026-06-18T20:34:30Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]npm/openclaw

AFFECTS (1)

[Software]npm/openclaw

HAS_WEAKNESS (1)

[Weakness]Missing Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph