Description
OpenClaw before 2026.4.25 contains a scope containment bypass vulnerability in device re-pairing that allows authenticated operators to restore broader scopes than intended by submitting empty-scope re-pairing requests. Attackers can exploit this by sending re-pairing requests with empty scope sets to skip containment guards and retain unauthorized device access.
Problem types
Not Failing Securely ('Failing Open')
Product status
Any version before 2026.4.25
2026.4.25 (semver)
Credits
zsx (@zsxsoft)
KeenSecurityLab
qclawer
References
github.com/...enclaw/security/advisories/GHSA-8mg9-j9cf-54cj (GitHub Security Advisory (GHSA-8mg9-j9cf-54cj))
www.vulncheck.com/...ypass-via-empty-scope-device-re-pairing (VulnCheck Advisory: OpenClaw < 2026.4.25 - Scope Bypass via Empty-Scope Device Re-pairing)