MEDIUM 5.4 npm
OpenClaw: Gateway `device.token.rotate` does not terminate active WebSocket sessions after credential rotation
GHSA-rfqg-qgf8-xr9x · CVE-2026-41356
Published · Modified
Description
Summary
Gateway device.token.rotate does not terminate active WebSocket sessions after credential rotation
Current Maintainer Triage
- Status: open
- Normalized severity: low
- Assessment: v2026.3.28 rotates device tokens without disconnecting already-authenticated WebSocket sessions, which is a real but post-compromise revocation gap.
Affected Packages / Versions
- Package:
openclaw(npm) - Latest published npm version:
2026.3.31 - Vulnerable version range:
<=2026.3.28 - Patched versions:
>= 2026.3.31 - First stable tag containing the fix:
v2026.3.31
Fix Commit(s)
91f7a6b0fd67b703897e6e307762d471ca09333d— 2026-03-31T09:05:34+09:00
Release Process Note
- The fix is already present in released version
2026.3.31. - This draft looks ready for final maintainer disposition or publication, not additional code-fix work.
Thanks @zsxsoft for reporting.
References
- WEB https://github.com/openclaw/openclaw/security/advisories/GHSA-rfqg-qgf8-xr9x
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-41356
- WEB https://github.com/openclaw/openclaw/commit/91f7a6b0fd67b703897e6e307762d471ca09333d
- PACKAGE https://github.com/openclaw/openclaw
- WEB https://github.com/openclaw/openclaw/releases/tag/v2026.3.31
- WEB https://www.vulncheck.com/advisories/openclaw-incomplete-websocket-session-termination-in-device-token-rotate
Ready to move
Start Securing
Free, no credit card | First findings in minutes