GHSA-pfv7-rr5m-qmv6
### Summary When the optional Chrome extension relay is enabled, `/extension` accepted unauthenticated WebSocket upgrades while `/json/*` and `/cdp` required auth. ### Affected Packages / Versions - Package: `openclaw` (npm) - Affected: `<= 2026.2.17` - Latest published npm version at triage time: `2026.2.17` ### Impact This is a local-only issue on loopback (`127.0.0.1`) and only applies when the extension relay feature is in use. A local process on the same machine could connect to `/extension` without the token and interfere with extension-relay behavior. No remote network exploit path is involved. ### Fix - Require gateway-token auth on both `/extension` and `/cdp` relay WebSocket endpoints. - Keep loopback/origin checks as defense-in-depth, not as authentication. - Use one token path in setup: `gateway.auth.token` / `OPENCLAW_GATEWAY_TOKEN`. ### Fix Commit(s) - `7e54b6c96feb1a5c30884f2b32037b8dadd0e532` OpenClaw thanks @tdjackey for reporting.
Properties
- ghsa_id
- GHSA-pfv7-rr5m-qmv6
- severity
- medium
- summary
- OpenClaw has auth inconsistency on local Browser Extension Relay /extension endpoint
- cve_id
- GHSA-pfv7-rr5m-qmv6
- is_ghsa_only
- true
- ghsa_published
- 2026-03-03T21:42:27Z
- source_url
- https://github.com/advisories/GHSA-pfv7-rr5m-qmv6
- ghsa_updated
- 2026-03-03T21:42:30Z
Related Entities (3)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph