lowCVSS 2.5Vulnerability

GHSA-vm29-7mq3-9jrg

### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-qvr7-g57c-mrc7. This link is maintained to preserve external references. ### Original Description OpenClaw before 2026.3.11 contains a credential fallback vulnerability where unavailable local gateway.auth.token and gateway.auth.password SecretRefs are treated as unset, allowing fallback to remote credentials in local mode. Attackers can exploit misconfigured local auth references to cause CLI and helper paths to select incorrect credential sources, potentially bypassing intended local authentication boundaries.

Properties

ghsa_id
GHSA-vm29-7mq3-9jrg
summary
Duplicate Advisory: OpenClaw: Unavailable local auth SecretRefs could fall through to remote credentials in local mode
severity
low
cvss_score
2.5
cve_id
GHSA-vm29-7mq3-9jrg
cvss_vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
is_ghsa_only
true
ghsa_published
2026-03-31T12:31:35Z
source_url
https://github.com/advisories/GHSA-vm29-7mq3-9jrg
ghsa_updated
2026-04-07T18:10:19Z

Related Entities (3)

HAS_WEAKNESS (1)

[Weakness]Not Failing Securely ('Failing Open')

REPORTED_BY (1)

[Source]GitHub Advisory Database

AFFECTS (1)

[Software]npm/OpenClaw

Explore deeper with Ninja Signal's threat intelligence graph