CVE-2026-32057
OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions
描述
## Summary A trusted-proxy Control UI pairing bypass accepted `client.id=control-ui` without device identity checks. The bypass did not require `operator` role, so an authenticated `node` role session could connect unpaired and reach node event methods. ## Impact With trusted-proxy authentication enabled, a `node` role websocket client could skip pairing by using `client.id=control-ui`. That created an authorization boundary bypass from a node-scoped connection into node event execution flows. ## Affected Packages / Versions - Package: `openclaw` (npm) - Affected range: `<= 2026.2.24` - Latest published vulnerable version: `2026.2.24` - Patched in next release: `2026.2.25` (pre-set below so this advisory is ready to publish after npm release) ## Fix The trusted-proxy Control UI bypass now additionally requires `role === "operator"`. ### Fix Commit(s) - `ec45c317f5d0631a3d333b236da58c4749ede2a3` ## Release Process Note `patched_versions` is intentionally pre-set to the release (`2026.2.25`). Advisory published with npm release `2026.2.25`.2.25` is published, the remaining GHSA action is to publish this advisory. OpenClaw thanks @tdjackey for reporting.
如何修補 CVE-2026-32057
要修補 CVE-2026-32057,請將受影響套件升級到下列已修補版本。
- —升級至 2026.2.25 或更新版本
CVE-2026-32057 正在被利用嗎?
低 — EPSS 為 0.3%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 2026.2.25
CVSS 分數
| 來源 | 版本 | 嚴重程度 |
|---|