MEDIUM
OpenClaw < 2026.3.22 - Premature Cite Expansion Before Authorization in Channel and DM
Published Apr 9, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.43%
Description
OpenClaw before 2026.3.22 performs cite expansion before completing channel and DM authorization checks, allowing cite work and content handling prior to final auth decisions. Attackers can exploit this timing vulnerability to access or manipulate content before proper authorization validation occurs.
Affected products
-
- Version 0StatusaffectedConstraints<2026.3.22
- Version 2026.3.22StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.3.22
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.3.22 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-21130 Advisory
- https://github.com/advisories/GHSA-vfg3-pqpq-93m4 Advisory
- https://github.com/openclaw/openclaw/commit/3cbf932413e41d1836cb91aed1541a28a3122f93 patch
- https://github.com/openclaw/openclaw/commit/630f1479c44f78484dfa21bb407cbe6f171dac87 patch
- https://github.com/openclaw/openclaw/commit/ebee4e2210e1f282a982c7ef2ad79d77a572fc87 patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-vfg3-pqpq-93m4 vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-35637
- https://www.vulncheck.com/advisories/openclaw-premature-cite-expansion-before-authorization-in-channel-and-dm third-party-advisoryThird Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 9, 2026
Updated Jun 23, 2026
Reserved Apr 4, 2026
Link CVE-2026-35637
CISA Vulnrichment
Updated Apr 10, 2026
ENISA EUVD
EUVD-2026-21130 GHSA-VFG3-PQPQ-93M4 Assigner VulnCheck
Published Apr 9, 2026
Updated Jun 23, 2026
Exploited since n/a
Link EUVD-2026-21130