Back to CVE List

CVE-2026-53824

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
6.5 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Vulnerability Description

OpenClaw before 2026.4.24 contains a token revocation vulnerability allowing callers with revoked slash tokens to continue executing commands during monitor refresh windows. Attackers can exploit stale token acceptance to invoke slash command behavior briefly after token revocation, potentially executing unauthorized actions depending on operator configuration.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-613
Source
NVD
Vendor
OpenClaw
Product
OpenClaw

External References

Discussion (0)

Add Comment

No comments yet. Be the first!