Executive brief
OpenClaw is a Node.js library used to build AI agents with authentication and prompt management. The vulnerability allows weak gateway authentication tokens to be reused as a fallback secret for obfuscating owner information in system prompts, which are visible to third-party AI model providers. Operators using weak tokens and relying on the automatic fallback are at risk of owner identity exposure.
Technical details
This vulnerability involves improper secret reuse (CWE-522): OpenClaw falls back to reusing gateway.auth.token or gateway.remote.token as the hash secret for owner-ID prompt obfuscation when commands.ownerDisplay=hash and commands.ownerDisplaySecret are not explicitly set. This creates dual-use of an authentication credential across two security domains—gateway authentication and prompt metadata hashing. The hash outputs are transmitted to third-party model providers in system prompts, potentially exposing the owner identity if the token is weak. No network or authentication preconditions are required for this exposure; it occurs automatically during normal operation. The patch removes the fallback behavior and auto-generates a dedicated commands.ownerDisplaySecret instead.
Affected products
- OpenClaw openclaw <=2026.2.21-2
Timeline
- 2026-03-03: disclosed
- 2026-03-03: patched: Planned fix in version 2026.2.22