Junglewise Threat Intelligence

CVE-2026-34511: OpenClaw PKCE verifier exposure in Gemini OAuth flow

CVE-2026-34511 · Severity: medium · CVSS 5.3 · Published 2026-04-03

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a library used for integrating with AI services, contains a security flaw in how it handles user logins via Google Gemini. The software accidentally shares a secret security code in the web address during the login process. If an attacker manages to see this web address, they could potentially hijack the user's session and gain unauthorized access to their account data.

Technical details

OpenClaw versions prior to 2026.4.2 fail to maintain independence between the OAuth 2.0 'state' parameter and the Proof Key for Code Exchange (PKCE) 'code_verifier'. In the Gemini OAuth flow, the application reuses the PKCE verifier as the state value. Because the OAuth provider reflects the state parameter back in the redirect URL, an attacker who intercepts the redirect URL (e.g., via browser history, logs, or referrer headers) obtains both the authorization code and the PKCE verifier. This bypasses the security protections provided by PKCE, allowing the attacker to exchange the intercepted code for a valid access token. The issue is addressed in version 2026.4.2 by using unique, independent values for the state and PKCE verifier.

Affected products

  • OpenClaw OpenClaw < 2026.4.2

Timeline

  • 2026-04-02: patched: Fix committed to main branch
  • 2026-04-02: advisory: GitHub Security Advisory published
  • 2026-04-03: disclosed: CVE published to NVD

References

Related threats