GHSA-8mg9-j9cf-54cj · Severity: low · Ecosystem: npm — OpenClaw: Empty-scope device re-pairing could confuse caller scope containment
OpenClaw before 2026.4.25 contains a scope containment bypass vulnerability in device re-pairing that allows authenticated operators to restore broader scopes than intended by submitting empty-scope re-pairing requests. Attackers can exploit this by sending re-pairing requests with empty scope sets to skip containment guards and retain unauthorized device access.
Conclusion & alert: CVE-2026-53852 is rated Low Risk (11.5/100): CVSS Low severity, with low exploitation likelihood (EPSS 0.17%). Mandatory action: Low composite risk—no urgent action required; patch on your normal maintenance cycle and revisit priority if CVSS or EPSS increases.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-17 | — | 0.17% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 2.3 | 4.0 | LOW |
|
— | — | [email protected] |
| 5.4 | 3.1 | MEDIUM |
|
2.8 | 2.5 | [email protected] |
GHSA-8mg9-j9cf-54cj · Severity: low · Ecosystem: npm — OpenClaw: Empty-scope device re-pairing could confuse caller scope containment
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| openclaw | openclaw | < 2026.4.25 | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
| openclaw | openclaw | 2026.4.25 | cpe:2.3:a:openclaw:openclaw:2026.4.25:beta1:*:*:*:node.js:*:* |
| openclaw | openclaw | 2026.4.25 | cpe:2.3:a:openclaw:openclaw:2026.4.25:beta10:*:*:*:node.js:*:* |
| openclaw | openclaw | 2026.4.25 | cpe:2.3:a:openclaw:openclaw:2026.4.25:beta11:*:*:*:node.js:*:* |
| openclaw | openclaw | 2026.4.25 | cpe:2.3:a:openclaw:openclaw:2026.4.25:beta2:*:*:*:node.js:*:* |
| openclaw | openclaw | 2026.4.25 | cpe:2.3:a:openclaw:openclaw:2026.4.25:beta3:*:*:*:node.js:*:* |
| openclaw | openclaw | 2026.4.25 | cpe:2.3:a:openclaw:openclaw:2026.4.25:beta4:*:*:*:node.js:*:* |
| openclaw | openclaw | 2026.4.25 | cpe:2.3:a:openclaw:openclaw:2026.4.25:beta5:*:*:*:node.js:*:* |
| openclaw | openclaw | 2026.4.25 | cpe:2.3:a:openclaw:openclaw:2026.4.25:beta6:*:*:*:node.js:*:* |
| openclaw | openclaw | 2026.4.25 | cpe:2.3:a:openclaw:openclaw:2026.4.25:beta7:*:*:*:node.js:*:* |
| openclaw | openclaw | 2026.4.25 | cpe:2.3:a:openclaw:openclaw:2026.4.25:beta8:*:*:*:node.js:*:* |
| openclaw | openclaw | 2026.4.25 | cpe:2.3:a:openclaw:openclaw:2026.4.25:beta9:*:*:*:node.js:*:* |
| URL | Tags |
|---|---|
| https://github.com/openclaw/openclaw/security/advisories/GHSA-8mg9-j9cf-54cj | Vendor Advisory |
| https://www.vulncheck.com/advisories/openclaw-scope-bypass-via-empty-scope-device-re-pairing | Third Party Advisory |