GHSA-83w9-h5wv-j9xm: OpenClaw: TOCTOU race bypasses node approval scope

GHSA-83w9-h5wv-j9xm HIGH
Published July 2, 2026
CISO Take

A TOCTOU race condition in OpenClaw's node pairing and reconnection flow lets a reconnecting node influence the approval-scope decision, potentially restoring broader node authority than the operator configured. This matters most for teams running shared or multi-tenant OpenClaw Gateways, where a previously revoked or lower-trust node could silently regain elevated access to tools and channels without triggering a fresh approval; the vendor rates it high severity even though there is no CVSS score, EPSS data, CISA KEV listing, or public exploit/scanner template published yet, so real-world exploitation likelihood is currently unconfirmed. OpenClaw itself carries a heavy security debt — 425 other CVEs recorded against the package and a package risk score of 0/100 — which raises the odds this specific bug sits alongside other exploitable weaknesses in the same deployment. Only 4 downstream dependents are tracked today, limiting blast radius, but any operator sharing one Gateway across mutually untrusted users or plugins should treat this as urgent. Upgrade to 2026.5.27 immediately, revoke all existing node pairings and re-pair only trusted nodes, and disable the affected pairing/reconnection feature if it isn't required.

Sources: GitHub Advisory CISA KEV ATLAS

What is the risk?

High severity per vendor rating, but exploitability signals are currently thin: no CVSS vector, no EPSS score, not listed in CISA KEV, and no public exploit code or Nuclei template exists. Exploitation requires the affected node-pairing/reconnection feature to be enabled and reachable by a lower-trust actor — realistically a multi-tenant Gateway shared between mutually untrusted users, or an environment where node re-pairing is externally triggerable. As a TOCTOU race condition (CWE-367), reliable exploitation demands precise timing rather than a trivial single request, placing it at moderate attacker sophistication. The real risk driver is systemic: openclaw has 425 other recorded CVEs and a package risk score of 0/100, indicating this bug is unlikely to be an isolated defect in an otherwise hardened codebase.

How does the attack unfold?

Node Reconnection
A previously paired or lower-trust node initiates reconnection to the Gateway, re-entering the pairing negotiation flow.
TOCTOU Race Exploitation
A race condition during pairing state mutation lets the reconnecting session influence the approval-scope decision before it is finalized and enforced.
AML.T0107
Authority Restoration
The node's authority is restored or broadened beyond what the operator's current configuration intends, bypassing the approval control.
Excessive Tool/Channel Access
With elevated node authority, the adversary invokes tools or reaches channels beyond the intended trust boundary.
AML.T0053

What systems are affected?

Package Ecosystem Vulnerable Range Patched
OpenClaw npm < 2026.5.27 2026.5.27
3 dependents 37% patched ~3d to patch Full package profile →

Do you use OpenClaw? You're affected.

How severe is it?

CVSS 3.1
N/A
EPSS
N/A
Exploitation Status
No known exploitation
Sophistication
Moderate

What should I do?

1 step
  1. Patch to openclaw 2026.5.27 or later immediately — this is the first version with the fix. Revoke all existing node pairings and re-pair only nodes you currently trust; don't assume existing pairings are still scoped correctly post-patch without re-verification. Keep channel and tool allowlists as narrow as possible, avoid sharing a single Gateway between mutually untrusted users, and disable the node pairing/reconnection feature entirely if it isn't operationally required. For detection, audit Gateway logs for unexpected re-pairing events, nodes whose effective scope changed without an explicit new approval, or reconnection bursts that could indicate race-condition probing. Since no CVSS/EPSS/exploit data exists yet, treat the vendor's 'high' severity rating and the CWE-367 race-condition class as the primary urgency signals rather than waiting for exploit telemetry.

How is it classified?

Which compliance frameworks are affected?

This CVE is relevant to:

EU AI Act
Article 15 - Accuracy, robustness and cybersecurity
ISO 42001
A.6.2.3 - AI system security controls
NIST AI RMF
MEASURE 2.7 - AI system security and resilience evaluation
OWASP LLM Top 10
LLM08 - Excessive Agency

Frequently Asked Questions

What is GHSA-83w9-h5wv-j9xm?

A TOCTOU race condition in OpenClaw's node pairing and reconnection flow lets a reconnecting node influence the approval-scope decision, potentially restoring broader node authority than the operator configured. This matters most for teams running shared or multi-tenant OpenClaw Gateways, where a previously revoked or lower-trust node could silently regain elevated access to tools and channels without triggering a fresh approval; the vendor rates it high severity even though there is no CVSS score, EPSS data, CISA KEV listing, or public exploit/scanner template published yet, so real-world exploitation likelihood is currently unconfirmed. OpenClaw itself carries a heavy security debt — 425 other CVEs recorded against the package and a package risk score of 0/100 — which raises the odds this specific bug sits alongside other exploitable weaknesses in the same deployment. Only 4 downstream dependents are tracked today, limiting blast radius, but any operator sharing one Gateway across mutually untrusted users or plugins should treat this as urgent. Upgrade to 2026.5.27 immediately, revoke all existing node pairings and re-pair only trusted nodes, and disable the affected pairing/reconnection feature if it isn't required.

Is GHSA-83w9-h5wv-j9xm actively exploited?

No confirmed active exploitation of GHSA-83w9-h5wv-j9xm has been reported, but organizations should still patch proactively.

How to fix GHSA-83w9-h5wv-j9xm?

Patch to openclaw 2026.5.27 or later immediately — this is the first version with the fix. Revoke all existing node pairings and re-pair only nodes you currently trust; don't assume existing pairings are still scoped correctly post-patch without re-verification. Keep channel and tool allowlists as narrow as possible, avoid sharing a single Gateway between mutually untrusted users, and disable the node pairing/reconnection feature entirely if it isn't operationally required. For detection, audit Gateway logs for unexpected re-pairing events, nodes whose effective scope changed without an explicit new approval, or reconnection bursts that could indicate race-condition probing. Since no CVSS/EPSS/exploit data exists yet, treat the vendor's 'high' severity rating and the CWE-367 race-condition class as the primary urgency signals rather than waiting for exploit telemetry.

What systems are affected by GHSA-83w9-h5wv-j9xm?

This vulnerability affects the following AI/ML architecture patterns: agent frameworks, agent orchestration/gateways, multi-tenant agent deployments.

What is the CVSS score for GHSA-83w9-h5wv-j9xm?

No CVSS score has been assigned yet.

What is the AI security impact?

Affected AI Architectures

agent frameworksagent orchestration/gatewaysmulti-tenant agent deployments

MITRE ATLAS Techniques

AML.T0053 AI Agent Tool Invocation
AML.T0107 Exploitation for Defense Evasion

Compliance Controls Affected

EU AI Act: Article 15
ISO 42001: A.6.2.3
NIST AI RMF: MEASURE 2.7
OWASP LLM Top 10: LLM08

What are the technical details?

Original Advisory

### Summary Node pairing reconnection could confuse approval scope state. In affected versions, a paired or reconnecting node session could mutate pairing state in a way that changed the approval scope decision. This advisory is scoped to the named feature and configuration. It does not change OpenClaw's trusted-operator model: authenticated Gateway operators, installed plugins, and intentional local execution surfaces remain trusted unless a separate policy, approval, allowlist, sandbox, or auth boundary is crossed. ### Impact When the affected feature is enabled and reachable, this could restore or present broader node authority than the operator intended. Practical impact depends on the operator's configuration and whether lower-trust input can reach that path. ### Patched Versions The first stable patched version is `2026.5.27`. ### Mitigations revoke unexpected node pairings and re-pair only trusted nodes until patched. As general hardening, keep channel and tool allowlists narrow, avoid sharing one Gateway between mutually untrusted users, and disable the affected feature when it is not needed.

Exploitation Scenario

An operator has previously scoped or partially revoked a node's authority within a shared OpenClaw Gateway — for example, downgrading a plugin or agent instance after a security review, or in a setup where multiple mutually untrusted teams pair nodes to the same Gateway. That node (or an adversary controlling it) initiates a reconnection. During the reconnection handshake, the approval-scope state gets mutated as part of pairing bookkeeping; because of the TOCTOU race, the reconnecting session can influence that mutation before the intended narrower scope is finalized and enforced. The node ends up reconnected with its prior, broader authority restored — potentially regaining access to tools, channels, or execution paths the operator meant to have revoked. From there, the adversary-controlled node invokes AI agent tools or reaches channels beyond its intended trust boundary, effectively achieving privilege escalation within the agent orchestration layer without needing to steal credentials or exploit the LLM itself.

Weaknesses (CWE)

CWE-367 — Time-of-check Time-of-use (TOCTOU) Race Condition: The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

  • [Implementation] The most basic advice for TOCTOU vulnerabilities is to not perform a check before the use. This does not resolve the underlying issue of the execution of a function on a resource whose state and identity cannot be assured, but it does help to limit the false sense of security given by the check.
  • [Implementation] When the file being altered is owned by the current user and group, set the effective gid and uid to that of the current user and group when executing this statement.

Source: MITRE CWE corpus.

Timeline

Published
July 2, 2026
Last Modified
July 2, 2026
First Seen
July 2, 2026

Related Vulnerabilities