Executive brief
OpenClaw is a CLI tool used for remote onboarding and gateway management. A flaw in the trust verification process allows attackers to inject a malicious endpoint URL that persists even after being declined by a user, causing gateway credentials to be sent to the attacker's controlled server if the operator subsequently accepts the prefilled URL prompt.
Technical details
The vulnerability is a trust-decline bypass in OpenClaw's remote onboarding functionality (CWE-670: Improper Error Handling). During remote onboarding, an attacker can inject a discovered endpoint URL; when a user declines this endpoint, the application fails to properly reset the URL, allowing it to persist into the subsequent manual configuration prompt. Since operator acceptance of the prefilled value is still required, the attack requires user interaction. An attacker who successfully exploits this can capture gateway credentials. The fix (commit 2a75416) properly resets the remote URL after trust decline and is available in version 2026.3.31 and later.
Affected products
- OpenClaw openclaw <=2026.3.28
Timeline
- 2026-04-03: disclosed: Advisory published
- 2026-03-30: patched: Fix committed; available in v2026.3.31
- 2026-04-21: other: Advisory modified/updated