CVE-2026-32057

HIGH7.1EPSS 0.09%

OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions

發布日:2026/3/3修改日:2026/3/30

描述

## Summary A trusted-proxy Control UI pairing bypass accepted `client.id=control-ui` without device identity checks. The bypass did not require `operator` role, so an authenticated `node` role session could connect unpaired and reach node event methods. ## Impact With trusted-proxy authentication enabled, a `node` role websocket client could skip pairing by using `client.id=control-ui`. That created an authorization boundary bypass from a node-scoped connection into node event execution flows. ## Affected Packages / Versions - Package: `openclaw` (npm) - Affected range: `<= 2026.2.24` - Latest published vulnerable version: `2026.2.24` - Patched in next release: `2026.2.25` (pre-set below so this advisory is ready to publish after npm release) ## Fix The trusted-proxy Control UI bypass now additionally requires `role === "operator"`. ### Fix Commit(s) - `ec45c317f5d0631a3d333b236da58c4749ede2a3` ## Release Process Note `patched_versions` is intentionally pre-set to the release (`2026.2.25`). Advisory published with npm release `2026.2.25`.2.25` is published, the remaining GHSA action is to publish this advisory. OpenClaw thanks @tdjackey for reporting.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 4.0CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
osvCVSS 3.1HIGH7.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

參考連結(5)