HIGH
OpenClaw < 2026.3.31 - Remote Code Execution via Node Scope Gate Bypass
Published Apr 23, 2026
7.7
HIGHCVSS 4.0
EPSS 1.05%
Description
OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node scope gate authentication mechanism. Attackers with device pairing credentials can execute arbitrary node commands on the host system without proper node pairing validation.
Affected products
-
- Version 0StatusaffectedConstraints<2026.3.31
- Version 2026.3.31StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.3.31
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.3.31 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://github.com/advisories/GHSA-xj9w-5r6q-x6v4 Advisory
- https://github.com/openclaw/openclaw/commit/3886b65ef21d02808c1a106fa1f9f69e22f71c32 patch
- https://github.com/openclaw/openclaw/releases/tag/v2026.3.31
- https://github.com/openclaw/openclaw/security/advisories/GHSA-xj9w-5r6q-x6v4 vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-41352
- https://www.vulncheck.com/advisories/openclaw-remote-code-execution-via-node-scope-gate-bypass third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-xj9w-5r6q-x6v4 | Advisory | |
| https://github.com/openclaw/openclaw/commit/3886b65ef21d02808c1a106fa1f9f69e22f71c32 | patch | |
| https://github.com/openclaw/openclaw/releases/tag/v2026.3.31 | ||
| https://github.com/openclaw/openclaw/security/advisories/GHSA-xj9w-5r6q-x6v4 | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-41352 | ||
| https://www.vulncheck.com/advisories/openclaw-remote-code-execution-via-node-scope-gate-bypass | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 23, 2026
Updated Apr 24, 2026
Reserved Apr 20, 2026
Link CVE-2026-41352
CISA Vulnrichment
GHSA-XJ9W-5R6Q-X6V4 Updated Apr 24, 2026