Insufficient Session Expiration in OpenClaw - #VU125287

 

Insufficient Session Expiration in OpenClaw - #VU125287

Published: April 8, 2026


Vulnerability identifier: #VU125287
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-613
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to maintain access to an existing WebSocket session after shared gateway token rotation.

The vulnerability exists due to insufficient session expiration in shared-token WebSocket sessions when rotating the shared gateway token. A remote user can continue using an existing WebSocket session to maintain access to an existing WebSocket session after shared gateway token rotation.


Affected software

OpenClaw

Remediation

Install security update from vendor's website.

OpenClaw - update to 2026.4.8

External References

Related Security Bulletins