Junglewise Threat Intelligence

CVE-2026-41345: OpenClaw authorization header leak in cross-origin media redirects

CVE-2026-41345 · Severity: medium · CVSS 4 · Published 2026-04-03

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a popular platform for media handling and downloads. When downloading media files, the application was forwarding sensitive authorization credentials to third-party domains if the download was redirected across different origins. An attacker controlling an intermediate domain in a redirect chain could intercept and steal authentication tokens, potentially gaining unauthorized access to user accounts and data.

Technical details

The vulnerability is an improper credential handling flaw (CWE-522) in OpenClaw's media download functionality. When a media download request with Authorization headers followed HTTP redirects, the application failed to strip authentication credentials before forwarding the request to cross-origin (different domain) destinations. An attacker can exploit this by crafting a redirect chain from a legitimate origin to an attacker-controlled domain, causing sensitive Authorization headers to leak to the attacker's server. No special authentication or privileges are required—any user initiating a media download through a malicious redirect path is vulnerable. The vulnerability was patched in version 2026.3.31 by dropping auth and cookie headers on cross-origin redirects while preserving them for same-origin redirect chains.

Affected products

  • OpenClaw OpenClaw <=2026.3.28

Timeline

  • 2026-04-03: disclosed: GHSA-68v4-hmwv-f43h published
  • 2026-03-31: patched: Fix committed in v2026.3.31

References

Related threats