Junglewise Threat Intelligence

CVE-2026-3691: OpenClaw Client PKCE verifier information disclosure in macOS onboarding

CVE-2026-3691 · Severity: medium · CVSS 5.3 · Published 2026-04-11

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

A security flaw in the OpenClaw macOS application's onboarding process could allow an attacker to intercept sensitive login credentials. This occurs when a user attempts to link their account via OAuth, as the application mistakenly includes secret verification data in the web address (URL). If exploited, this could lead to unauthorized access to the user's connected services and personal data.

Technical details

An information disclosure vulnerability exists in the OpenClaw macOS beta onboarding flow due to the improper handling of PKCE (Proof Key for Code Exchange) secrets. The application incorrectly uses the 'code_verifier' value as the OAuth 'state' parameter, causing the secret to be exposed in the front-channel URL query string. A remote attacker could intercept this sensitive data if a user initiates an OAuth authorization flow. Successful exploitation requires the attacker to obtain both the OAuth authorization artifacts and the exposed state values, potentially leading to credential theft. The issue was addressed in version 2026.2.25 by removing the vulnerable Anthropic OAuth sign-in path in favor of setup tokens.

Affected products

  • OpenClaw OpenClaw <= 2026.2.24

Timeline

  • 2026-02-25: disclosed: Vulnerability reported to vendor
  • 2026-02-26: patched: Vendor released version 2026.2.25 and advisory GHSA-6g25-pc82-vfwp
  • 2026-03-30: advisory: ZDI published advisory ZDI-26-229

References

Related threats