CVE-2026-41352

OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node scope gate authentication mechanism. Attackers with device pairing credentials can execute arbitrary node commands on the host system without proper node pairing validation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

28 Apr 2026, 18:54

Type Values Removed Values Added
References () https://github.com/openclaw/openclaw/commit/3886b65ef21d02808c1a106fa1f9f69e22f71c32 - () https://github.com/openclaw/openclaw/commit/3886b65ef21d02808c1a106fa1f9f69e22f71c32 - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-xj9w-5r6q-x6v4 - () https://github.com/openclaw/openclaw/security/advisories/GHSA-xj9w-5r6q-x6v4 - Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-remote-code-execution-via-node-scope-gate-bypass - () https://www.vulncheck.com/advisories/openclaw-remote-code-execution-via-node-scope-gate-bypass - Third Party Advisory
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
First Time Openclaw openclaw
Openclaw

23 Apr 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-23 22:16

Updated : 2026-04-28 18:54


NVD link : CVE-2026-41352

Mitre link : CVE-2026-41352

CVE.ORG link : CVE-2026-41352


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-862

Missing Authorization