PT-2026-32057 · Npm · Openclaw

Publicado

2026-03-31

·

Atualizado

2026-03-31

CVSS v3.1

7.3

Alta

VetorAV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Summary

Remote onboarding accepted discovered gateway endpoints without an explicit trust confirmation before persisting the remote URL and connection details.

Impact

A malicious or spoofed discovery endpoint could steer onboarding toward an attacker-controlled gateway and capture future gateway credentials or traffic.

Affected Component

src/commands/onboard-remote.ts

Fixed Versions

  • Affected: <= 2026.3.24
  • Patched: >= 2026.3.28
  • Latest stable 2026.3.28 contains the fix.

Fix

Fixed by commit d6affb17d8 (CLI: confirm discovered remote gateways before saving config).

Correção

Missing Authorization

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-3CW3-5VXW-G2H3

Produtos afetados

Openclaw