Junglewise Threat Intelligence

CVE-2026-59261: OpenClaw credential exposure via workspace dotenv files

CVE-2026-59261 · Severity: high · CVSS 7.1 · Published 2026-07-08

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a tool used for managing workspace environments and provider integrations, is vulnerable to a credential exposure flaw. An attacker with limited access to a workspace can use specially crafted configuration files to override and steal sensitive login credentials or other private data. This could lead to unauthorized access to connected services and the exposure of corporate secrets.

Technical details

A credential exposure vulnerability exists in OpenClaw versions prior to 2026.5.28 due to improper handling of workspace configuration files. The application allows '.env' (dotenv) files within a workspace to override global provider credentials, a flaw categorized as an incomplete list of disallowed inputs (CWE-184). An attacker with the ability to modify or provide input to a workspace path can craft a dotenv file that redirects or captures sensitive credentials intended for trusted providers. Exploitation requires local access and some level of user interaction or reachability to the configured input path. The issue is resolved in version 2026.5.28.

Affected products

  • OpenClaw OpenClaw < 2026.5.28

Timeline

  • 2026-06-30: advisory: GitHub Security Advisory published
  • 2026-07-08: disclosed: CVE published to NVD

References

Related threats