Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. openclaw
  4. ›
  5. CVE-2026-53816

CVE-2026-53816: OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance

July 2, 2026

OpenClaw nodes send lifecycle events back to the gateway. In affected releases, a paired node could send an exec lifecycle event that was accepted without enough provenance tying it to an authorized system.run request.

This issue affects the node event boundary. It does not allow an unauthenticated caller to reach the gateway; the attacker must already control a paired node connection.

References

  • github.com/advisories/GHSA-3c6j-hq33-3jv4
  • github.com/openclaw/openclaw/security/advisories/GHSA-3c6j-hq33-3jv4
  • nvd.nist.gov/vuln/detail/CVE-2026-53816
  • www.vulncheck.com/advisories/openclaw-exec-lifecycle-event-forgery-via-paired-node

Code Behaviors & Features

Detect and mitigate CVE-2026-53816 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2026.5.18

Fixed versions

  • 2026.5.18

Solution

Upgrade to version 2026.5.18 or above.

Impact 7.2 HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-284: Improper Access Control
  • CWE-862: Missing Authorization
  • CWE-863: Incorrect Authorization

Source file

npm/openclaw/CVE-2026-53816.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Thu, 16 Jul 2026 00:19:50 +0000.