CVE-2026-33579: 
OpenClaw (formerly Moltbot or Clawdbot) vulnerability analysis and mitigation

Overview

CVE-2026-33579 is a privilege escalation vulnerability in OpenClaw (npm package), a Node.js-based AI agent platform, affecting all versions prior to 2026.3.28. The flaw exists in the /pair approve command path, which fails to forward caller scopes into the core device approval check, allowing a low-privileged user with pairing rights to approve device requests for broader scopes — including admin access. It was published on March 31, 2026, with the canonical advisory being GHSA-hc5h-pmr3-3497 (GHSA-f275-5h5c-5wg5 is a duplicate, withdrawn on April 6, 2026). The vulnerability carries a CVSS v3.1 base score of 9.9 (Critical) and a CVSS v4.0 base score of 9.4 (Critical) (GitHub Advisory, Github Advisory).

Technical details

The root cause is classified as CWE-863 (Incorrect Authorization): the /pair approve command handler in extensions/device-pair/index.ts invokes the core device approval function in src/infra/device-pairing.ts without subsetting or forwarding the caller's own privilege scopes into the approval check. As a result, the approval logic does not validate whether the approving caller actually holds the scopes being granted to the requesting device. An attacker with pairing privileges (but not admin privileges) can craft or identify a pending device pairing request that asks for admin-level scopes, then invoke /pair approve to grant those elevated scopes without possessing them. The fix, introduced in commit 4ee4960de2, ensures caller scopes are forwarded during the approval flow (GitHub Advisory, Github Advisory).

Impact

Successful exploitation allows a low-privileged user to escalate their privileges to administrator level within an OpenClaw deployment, gaining full control over the platform's configuration, connected devices, and data. Because the attack is network-accessible and requires no user interaction, it can be executed remotely and potentially automated at scale. The CVSS v4.0 scoring reflects high impact across confidentiality, integrity, and availability for both the vulnerable system and subsequent systems, meaning compromised admin access could be leveraged for lateral movement, data exfiltration, or disruption of AI agent workflows (GitHub Advisory, Feedly).

Exploitability

A proof-of-concept repository was identified on GitHub (https://github.com/atalovesyou/openclaw-security-checker), though analysis indicates it contains only an index.html file with no functional exploit code, and is assessed as not a real exploit. There is no confirmed evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.01% (0.000100), indicating low automated exploitation probability currently. The vulnerability is not listed in the CISA KEV catalog. Community discussion across Reddit, Hacker News, Ars Technica, and Mashable has been significant, with security experts advising OpenClaw users to assume compromise if running unpatched versions (Github Advisory, Ars Technica).

Exploitation steps

  1. Reconnaissance: Identify an OpenClaw deployment running a version ≤ 2026.3.24 (vulnerable). Confirm the target is accessible over the network and that you have or can obtain an account with pairing privileges (e.g., via a free/self-service account).
  2. Initiate a device pairing request: Using a controlled device or client, submit a device pairing request to the OpenClaw instance that explicitly requests admin-level scopes in the pairing payload.
  3. Invoke /pair approve: Authenticate as the low-privileged user with pairing rights and issue the /pair approve command targeting the pending device request. Because extensions/device-pair/index.ts does not forward the caller's scopes into the core approval check in src/infra/device-pairing.ts, the approval succeeds regardless of the caller's actual privilege level.
  4. Obtain admin access: The approved device now holds admin-level scopes. Use the paired device's credentials or session to access admin-restricted functionality, modify configurations, access sensitive data, or further compromise connected systems (GitHub Advisory).

Indicators of compromise

  • Logs: Audit logs showing /pair approve commands issued by accounts that do not hold admin privileges; device pairing approval events where the approved scope set exceeds the approving caller's own scope set.
  • Application State: Devices or sessions with admin-level scopes that were approved by non-admin users; unexpected new admin-privileged devices appearing in the device registry.
  • Network: Unusual API calls to the /pair approve endpoint from low-privileged accounts, particularly if followed by admin-level API activity from newly paired devices.
  • User Activity: Non-admin accounts performing administrative actions (configuration changes, user management, data access) shortly after a device pairing approval event (GitHub Advisory).

Mitigation and workarounds

Upgrade OpenClaw (npm package openclaw) to version 2026.3.28 or later, which contains the fix introduced in commit 4ee4960de2 ("Pairing: forward caller scopes during approval"). Until patching is complete, restrict pairing privileges to only fully trusted, admin-equivalent users, and monitor device pairing approval logs for any approvals where the granted scopes exceed the approving user's own privileges. Removing pairing privileges from non-admin accounts entirely is the most effective interim workaround (GitHub Advisory, Github Advisory).

Community reactions

The vulnerability generated substantial community attention shortly after disclosure. Multiple Reddit threads across r/sysadmin, r/netsec, r/cybersecurity, and r/programming carried the headline "If you're running OpenClaw, you probably got hacked," reflecting significant alarm among system administrators. Ars Technica published a piece advising OpenClaw users to assume compromise, and Mashable described it as a "frightening" vulnerability. Security researchers on Mastodon and Bluesky amplified the disclosure, and TLDR InfoSec included it in their April 8, 2026 newsletter. The Hacker News community also engaged heavily, with the story reportedly reaching ~894 points. The OpenClaw maintainer credited @AntAISecurityLab for responsible disclosure (Ars Technica, GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related OpenClaw (formerly Moltbot or Clawdbot) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-102990HIGH8.2
  • JavaScript logoJavaScript
  • rust-std-static-aarch64-unknown-none-softfloat
NoYesSep 30, 2026
CVE-2026-101916HIGH7.4
  • JavaScript logoJavaScript
  • @grpc/grpc-js
NoYesSep 28, 2026
CVE-2026-102282HIGH7.1
  • JavaScript logoJavaScript
  • gjs-devel
NoYesOct 05, 2026
CVE-2026-101899MEDIUM6.9
  • JavaScript logoJavaScript
  • langfuse-3
NoYesSep 30, 2026
CVE-2026-101915LOW3.7
  • JavaScript logoJavaScript
  • zitadel-4
NoYesSep 28, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management