GHSA-xr4f-mjxj-w6w5: OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes
The bundled device-pair plugin exposed /pair on normal chat command surfaces. In affected releases, authorized non-owner chat senders could issue device-pairing bootstrap codes without having owner, admin, or pairing scope.
This issue does not affect unauthenticated users. The caller must already be allowed to send commands to the agent through a configured chat channel.
References
Code Behaviors & Features
Detect and mitigate GHSA-xr4f-mjxj-w6w5 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →