CVE-2026-53824

OpenClaw before 2026.4.24 contains a token revocation vulnerability allowing callers with revoked slash tokens to continue executing commands during monitor refresh windows. Attackers can exploit stale token acceptance to invoke slash command behavior briefly after token revocation, potentially executing unauthorized actions depending on operator configuration.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

16 Jun 2026, 02:51

Type Values Removed Values Added
First Time Openclaw
Openclaw openclaw
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-4m3v-q747-pc6h - () https://github.com/openclaw/openclaw/security/advisories/GHSA-4m3v-q747-pc6h - Mitigation, Vendor Advisory
References () https://www.vulncheck.com/advisories/mattermost-slash-token-revocation-lag-via-monitor-refresh-delay - () https://www.vulncheck.com/advisories/mattermost-slash-token-revocation-lag-via-monitor-refresh-delay - Third Party Advisory

12 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-12 22:16

Updated : 2026-06-17 10:58


NVD link : CVE-2026-53824

Mitre link : CVE-2026-53824

CVE.ORG link : CVE-2026-53824


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-613

Insufficient Session Expiration