CVE-2026-53824
MEDIUM SEVERITYCVSS Score & Metrics
Base Score
6.5 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Vulnerability Description
OpenClaw before 2026.4.24 contains a token revocation vulnerability allowing callers with revoked slash tokens to continue executing commands during monitor refresh windows. Attackers can exploit stale token acceptance to invoke slash command behavior briefly after token revocation, potentially executing unauthorized actions depending on operator configuration.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-613
Source
NVD
Vendor
OpenClaw
Product
OpenClaw
Discussion (0)
Add Comment
No comments yet. Be the first!