PT-2026-32057 · Npm · Openclaw

Published

2026-03-31

·

Updated

2026-03-31

CVSS v3.1

7.3

High

VectorAV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Summary

Remote onboarding accepted discovered gateway endpoints without an explicit trust confirmation before persisting the remote URL and connection details.

Impact

A malicious or spoofed discovery endpoint could steer onboarding toward an attacker-controlled gateway and capture future gateway credentials or traffic.

Affected Component

src/commands/onboard-remote.ts

Fixed Versions

  • Affected: <= 2026.3.24
  • Patched: >= 2026.3.28
  • Latest stable 2026.3.28 contains the fix.

Fix

Fixed by commit d6affb17d8 (CLI: confirm discovered remote gateways before saving config).

Fix

Missing Authorization

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-3CW3-5VXW-G2H3

Affected Products

Openclaw