Executive brief
OpenClaw is an AI automation platform that connects to various collaboration and messaging services through configured connector endpoints. A workspace-level environment configuration file (.env) can override the operator-controlled connector endpoints for Matrix, Mattermost, IRC, and Synology services, allowing an attacker with workspace access to redirect traffic to malicious servers and intercept or manipulate communications.
Technical details
The vulnerability is a configuration override issue (CWE-427, CWE-610) in OpenClaw's dotenv loading mechanism. Workspace-level .env files can set connector endpoint variables (including per-account Matrix homeserver suffixes and generic base-url/API-host style overrides) that take precedence over operator-configured endpoints for Matrix, Mattermost, IRC, and Synology connectors. An attacker with write access to a workspace's configuration can inject malicious endpoint variables, causing the runtime to connect to attacker-controlled servers instead of legitimate services. This requires workspace access and is patched in version 2026.4.22, which now blocks endpoint variables in workspace dotenv files while preserving trusted global runtime dotenv loading.
Affected products
- OpenClaw openclaw <= 2026.4.21
Timeline
- 2026-05-04: disclosed: Advisory published
- 2026-04-23: patched: Fix published in version 2026.4.22
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-55cf-xx38-4p9p
- https://github.com/openclaw/openclaw/commit/0623079e98abf7202591f1b04a89755eb7ec9272
- https://github.com/openclaw/openclaw
- https://www.vulncheck.com/advisories/openclaw-connector-endpoint-host-override-via-workspace-dotenv-files