Description
OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers with network access to spoof locality information and obtain durable admin-capable device tokens. Attackers can exploit insufficient locality-derived trust validation to convert temporary shared access into persistent administrative credentials that survive token rotation.
Problem types
Authentication Bypass by Spoofing
Product status
Any version before 2026.5.22
2026.5.22 (semver)
Credits
cantinagen
References
github.com/...enclaw/security/advisories/GHSA-chr9-m4q2-76hw (GitHub Security Advisory (GHSA-chr9-m4q2-76hw))
www.vulncheck.com/...-ui-locality-spoofing-in-device-pairing