lowCVSS 4.2Vulnerability

GHSA-h9h6-pwqv-j9hv

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-9v8j-9c9g-w66c. This link is maintained to preserve external references. ## Original Description OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerability allowing callers with pending token access to reuse tokens with broader requested scopes. Attackers can replay bootstrap tokens before approval to escalate pairing authority beyond intended scope limits.

Properties

ghsa_id
GHSA-h9h6-pwqv-j9hv
summary
Duplicate Advisory: Bootstrap token replay could widen pending pairing scopes
severity
low
cvss_score
4.2
cve_id
GHSA-h9h6-pwqv-j9hv
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
is_ghsa_only
true
ghsa_published
2026-06-16T21:32:00Z
source_url
https://github.com/advisories/GHSA-h9h6-pwqv-j9hv
ghsa_updated
2026-06-18T20:12:25Z

Related Entities (4)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/openclaw

AFFECTS (1)

[Software]npm/openclaw

HAS_WEAKNESS (1)

[Weakness]Incorrect Privilege Assignment

Explore deeper with Ninja Signal's threat intelligence graph