OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node scope gate authentication mechanism. Attackers with device pairing credentials can execute arbitrary node commands on the host system without proper node pairing validation.
References
Configurations
History
28 Apr 2026, 18:54
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/openclaw/openclaw/commit/3886b65ef21d02808c1a106fa1f9f69e22f71c32 - Patch | |
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-xj9w-5r6q-x6v4 - Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-remote-code-execution-via-node-scope-gate-bypass - Third Party Advisory | |
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| First Time |
Openclaw openclaw
Openclaw |
23 Apr 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-23 22:16
Updated : 2026-04-28 18:54
NVD link : CVE-2026-41352
Mitre link : CVE-2026-41352
CVE.ORG link : CVE-2026-41352
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-862
Missing Authorization
