Executive brief
OpenClaw is a Node.js library for building and managing Telegram bots. The library was logging Telegram bot API tokens in error messages, stack traces, and crash reports without redaction, potentially exposing credentials to developers, logging systems, CI/CD pipelines, and support staff. An attacker who obtains an exposed bot token can impersonate the bot and gain full control over its Bot API access, allowing them to read messages, send commands, or manipulate bot behavior.
Technical details
The vulnerability is an insufficiently protected credentials issue (CWE-522) where Telegram bot tokens appearing in request URLs (e.g., https://api.telegram.org/bot<token>/...) were logged without sanitization. The root cause is the absence of log redaction for sensitive data in error handling and stack trace output. Attack vector is local—tokens are exposed via logs, crash reports, CI output, and support bundles, requiring no network access or authentication bypass. An attacker with read access to logs or bundles can extract the token and use it to take over the bot. The fix (commit cf69907015b659e5025efb735ee31bd05c4ee3d5) implements token redaction in logging; patched version is 2026.2.15 or later.
Affected products
- OpenClaw openclaw <=2026.2.14
Timeline
- 2026-02-18: disclosed: GHSA-chf7-jq6g-qrwv published
- 2026-02-15: patched: Fix commit cf69907015b659e5025efb735ee31bd05c4ee3d5 available; version 2026.2.15 expected