OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired nodes to confuse approval scope decisions. Attackers can exploit reconnection logic to restore or present broader node authority than intended, potentially bypassing approval restrictions.
References
| Link | Resource |
|---|---|
| https://github.com/openclaw/openclaw/security/advisories/GHSA-83w9-h5wv-j9xm | Mitigation Vendor Advisory |
| https://www.vulncheck.com/advisories/openclaw-node-pairing-state-mutation-via-reconnection | Third Party Advisory |
Configurations
History
23 Jul 2026, 09:10
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
16 Jun 2026, 02:54
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Openclaw
Openclaw openclaw |
|
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-83w9-h5wv-j9xm - Mitigation, Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-node-pairing-state-mutation-via-reconnection - Third Party Advisory |
12 Jun 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-12 22:16
Updated : 2026-07-23 09:10
NVD link : CVE-2026-53838
Mitre link : CVE-2026-53838
CVE.ORG link : CVE-2026-53838
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
