OpenClaw before 2026.4.14 contains a redaction bypass vulnerability that allows authenticated gateway clients to receive unredacted secrets through sourceConfig and runtimeConfig alias fields. Attackers with config read access can exploit this to obtain provider API keys, gateway authentication material, and channel credentials that should have been redacted.
References
Configurations
History
No history.
Information
Published : 2026-05-05 12:16
Updated : 2026-06-17 10:49
NVD link : CVE-2026-43528
Mitre link : CVE-2026-43528
CVE.ORG link : CVE-2026-43528
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
