GHSA-vvgp-4c28-m3jm: OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions
A trusted-proxy Control UI pairing bypass accepted client.id=control-ui without device identity checks. The bypass did not require operator role, so an authenticated node role session could connect unpaired and reach node event methods.
References
Code Behaviors & Features
Detect and mitigate GHSA-vvgp-4c28-m3jm with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →