Junglewise Threat Intelligence

CVE-2026-53840: OpenClaw information disclosure in streamable-http MCP servers

CVE-2026-53840 · Severity: high · CVSS 7.1 · Published 2026-06-16

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, an AI assistant platform, contains a vulnerability where sensitive authentication data like API keys can be leaked to unauthorized third parties. This occurs when the software connects to a remote server that issues a redirect to a different web address. If an attacker controls the initial server or it becomes compromised, they can capture the credentials intended only for that specific service.

Technical details

OpenClaw's Model Context Protocol (MCP) implementation fails to strip custom HTTP headers when following cross-origin redirects for 'streamable-http' transports. An attacker who controls a configured MCP endpoint can issue a redirect to an arbitrary origin, causing the OpenClaw client to forward sensitive headers (such as API keys or tenant IDs) to the new location. This vulnerability is classified as CWE-200 (Exposure of Sensitive Information). The issue is resolved in version 2026.5.12, with partial mitigations available in 2026.5.8.

Affected products

  • OpenClaw openclaw < 2026.5.12

Timeline

  • 2026-05-28: disclosed
  • 2026-06-17: advisory: GitHub Advisory published
  • 2026-05-12: patched: First stable patched version released

References

Related threats