PT-2026-25417 · Npm · Openclaw
Published
2026-03-03
·
Updated
2026-03-03
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Description
In affected releases, when an operator explicitly enabled
gateway.controlUi.allowInsecureAuth: true and exposed the gateway over plaintext HTTP, Control UI authentication could permit privileged operator access without the intended device identity + pairing guarantees.This required an insecure deployment choice and credential exposure risk (for example, plaintext transit or prior token leak). It was fixed on
main in commit 40a292619e1f2be3a3b1db663d7494c9c2dc0abf (PR #20684).Affected Packages / Versions
- Package:
openclaw(npm) - Affected published versions:
<= 2026.2.19-2 - Planned patched version:
2026.2.21
Impact
In these explicitly insecure deployments, an attacker with leaked/intercepted credentials could obtain high-privilege Control UI access.
Fix Commit(s)
40a292619e1f2be3a3b1db663d7494c9c2dc0abf(merged 2026-02-20)
OpenClaw thanks @Vasco0x4 for reporting.
Fix
Cleartext Transmission of Sensitive Information
Improper Authorization
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw