highCVSS 5.9Vulnerability

GHSA-qwmf-95r9-gx9x

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-hff7-ccv5-52f8. This link is maintained to preserve external references. ## Original Description OpenClaw versions prior to 2026.2.21 incorrectly apply tokenless Tailscale header authentication to HTTP gateway routes, allowing bypass of token and password requirements. Attackers on trusted networks can exploit this misconfiguration to access HTTP gateway routes without proper authentication credentials.

Properties

ghsa_id
GHSA-qwmf-95r9-gx9x
severity
high
summary
Duplicate Advisory: OpenClaw's gateway tokenless Tailscale auth applied to HTTP routes
cvss_score
5.9
cve_id
GHSA-qwmf-95r9-gx9x
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
is_ghsa_only
true
ghsa_published
2026-03-21T03:31:13Z
source_url
https://github.com/advisories/GHSA-qwmf-95r9-gx9x
ghsa_updated
2026-03-24T18:05:56Z

Related Entities (3)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (1)

[Weakness]Authentication Bypass by Spoofing

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph