SB2026052913 - Multiple vulnerabilities in OpenClaw
Published: May 29, 2026 Updated: June 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 5 vulnerabilities.
1) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: N/A)
CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVSSv4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to obtain broader node authority than intended.
The vulnerability exists due to a time-of-check time-of-use race condition in the node pairing reconnection feature when handling paired or reconnecting node sessions. A remote user can manipulate pairing state transitions to obtain broader node authority than intended.
Only instances with the affected feature enabled and reachable are vulnerable. Practical impact depends on operator configuration and whether lower-trust input can reach the affected path.
2) Untrusted search path (CVE-ID: N/A)
CWE-ID: CWE-426 - Untrusted Search Path
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute an unintended executable.
The vulnerability exists due to improper control of executable selection in the skill install helper when processing a workspace .env file during skill install flows. A local user can place a crafted .env file in a repository to execute an unintended executable.
Only installations with the affected feature enabled and reachable are vulnerable.
3) Insufficiently protected credentials (CVE-ID: N/A)
CWE-ID: CWE-522 - Insufficiently Protected Credentials
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to insufficiently protected credentials in the MS Teams outbound requests feature when handling lower-trust caller input or configured input paths. A remote user can trigger outbound requests through a reachable affected path to disclose sensitive information.
Only instances where the affected feature is enabled and reachable are vulnerable, and practical impact depends on whether lower-trust input can reach that path.
4) Incorrect authorization (CVE-ID: N/A)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute or persist actions beyond the caller's intended authorization.
The vulnerability exists due to incorrect authorization in QQBot exec approvals when handling requests through the affected feature and configuration. A remote user can invoke a lower-trust caller or configured input path to execute or persist actions beyond the caller's intended authorization.
Only instances where the affected feature is enabled and reachable are vulnerable, and practical impact depends on whether lower-trust input can reach that path.
5) Missing Authorization (CVE-ID: N/A)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to bypass authorization checks.
The vulnerability exists due to missing authorization in device.pair.approve when handling lower-trust caller requests or configured input paths. A remote user can invoke the affected feature through a reachable lower-trust path to bypass authorization checks.
Exploitation is possible only when the affected feature is enabled and reachable.
Remediation
Install update from vendor's website.
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-83w9-h5wv-j9xm
- https://github.com/openclaw/openclaw/security/advisories/GHSA-8wg3-5mcm-fjq8
- https://github.com/openclaw/openclaw/security/advisories/GHSA-v54h-q2vx-vgg4
- https://github.com/openclaw/openclaw/security/advisories/GHSA-7jx6-764p-fgg9
- https://github.com/openclaw/openclaw/security/advisories/GHSA-8v95-qqcm-qp9h