PT-2026-31975 · Openclaw · Openclaw
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.25
Description
OpenClaw contains an authentication bypass issue in the raw card send surface. This allows unpaired recipients to create legacy callback payloads, bypassing DM pairing restrictions and reaching callback handling without authorization. The issue was resolved by rejecting legacy raw-card command payloads, ensuring callbacks remain on the normal paired path.
Recommendations
Update to version 2026.3.25 or later.
Exploit
Fix
Incorrect Authorization
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw