Executive brief
OpenClaw is a popular platform for media handling and downloads. When downloading media files, the application was forwarding sensitive authorization credentials to third-party domains if the download was redirected across different origins. An attacker controlling an intermediate domain in a redirect chain could intercept and steal authentication tokens, potentially gaining unauthorized access to user accounts and data.
Technical details
The vulnerability is an improper credential handling flaw (CWE-522) in OpenClaw's media download functionality. When a media download request with Authorization headers followed HTTP redirects, the application failed to strip authentication credentials before forwarding the request to cross-origin (different domain) destinations. An attacker can exploit this by crafting a redirect chain from a legitimate origin to an attacker-controlled domain, causing sensitive Authorization headers to leak to the attacker's server. No special authentication or privileges are required—any user initiating a media download through a malicious redirect path is vulnerable. The vulnerability was patched in version 2026.3.31 by dropping auth and cookie headers on cross-origin redirects while preserving them for same-origin redirect chains.
Affected products
- OpenClaw OpenClaw <=2026.3.28
Timeline
- 2026-04-03: disclosed: GHSA-68v4-hmwv-f43h published
- 2026-03-31: patched: Fix committed in v2026.3.31