Description
OpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/device-bootstrap.ts. Attackers can verify a valid bootstrap code multiple times before approval to escalate pending pairing scopes, including privilege escalation to operator.admin.
Problem types
Authentication Bypass by Capture-replay
Product status
Any version before 2026.3.13
2026.3.13 (semver)
Credits
tdjackey
References
github.com/...enclaw/security/advisories/GHSA-63f5-hhc7-cx6p (GitHub Security Advisory (GHSA-63f5-hhc7-cx6p))
github.com/...ommit/1803d16d5cec970c54b0e1ac46b31b1cbade335c (Patch Commit)
www.vulncheck.com/...ap-setup-code-replay-via-device-pairing (VulnCheck Advisory: OpenClaw < 2026.3.13 - Bootstrap Setup Code Replay via Device Pairing)