OpenClaw Authentication Rate Limiting Bypass Vulnerability
Vulnerability
A vulnerability in OpenClaw versions prior to 2026.3.31 allows attackers to bypass authentication rate limiting by using fake device tokens. This issue arises from the mixed WebSocket authentication flow, which can be exploited to circumvent shared authentication protections. As a result, attackers may conduct brute force attacks against weak shared passwords.
Impact
Exploitation of this vulnerability allows for authentication rate limiting bypass, enabling brute force attacks on shared passwords.
Reproduction
The vulnerability can be reproduced by initiating a WebSocket connection and sending a fake device token along with the authentication request. This will bypass the shared authentication rate limits and allow for repeated attempts to guess weak shared passwords.
Remediation
Users can upgrade to OpenClaw version 2026.3.31 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
