Canvas Capability Revocation Bypass in OpenClaw by OpenClaw
CVE-2026-100554
2.3LOW
What is CVE-2026-100554?
The OpenClaw npm package experiences a vulnerability that fails to immediately invalidate Canvas HTTP authorization upon node revocation. While a revoked node will lose its WebSocket client capabilities, it retains Canvas HTTP authorization until a cleanup process occurs, allowing it to exploit its capabilities on designated routes momentarily. This issue affects versions from 2026.5.12 to under 2026.8.1 and has been addressed in version 2026.8.1. To mitigate the risk during the cleanup, a workaround involves restarting the Gateway after revoking a node with Canvas access.
Affected Version(s)
OpenClaw 2026.5.12 < 2026.8.1
OpenClaw 2026.8.1
