CVE-2026-43528

OpenClaw before 2026.4.14 contains a redaction bypass vulnerability that allows authenticated gateway clients to receive unredacted secrets through sourceConfig and runtimeConfig alias fields. Attackers with config read access can exploit this to obtain provider API keys, gateway authentication material, and channel credentials that should have been redacted.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-05-05 12:16

Updated : 2026-06-17 10:49


NVD link : CVE-2026-43528

Mitre link : CVE-2026-43528

CVE.ORG link : CVE-2026-43528


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-212

Improper Removal of Sensitive Information Before Storage or Transfer