CVE-2026-53824

OpenClaw before 2026.4.24 contains a token revocation vulnerability allowing callers with revoked slash tokens to continue executing commands during monitor refresh windows. Attackers can exploit stale token acceptance to invoke slash command behavior briefly after token revocation, potentially executing unauthorized actions depending on operator configuration.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-06-12 22:16

Updated : 2026-07-23 09:10


NVD link : CVE-2026-53824

Mitre link : CVE-2026-53824

CVE.ORG link : CVE-2026-53824


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-613

Insufficient Session Expiration