Executive brief
OpenClaw, a tool used for managing Model Context Protocol (MCP) connections, contains a flaw where sensitive login credentials can be accidentally shared with unauthorized third-party servers. If an attacker can trigger a specific type of network redirect, they may capture the user's authorization headers, potentially allowing them to perform actions as that user. This could lead to unauthorized access to private data or services managed by the platform.
Technical details
A credential leakage vulnerability exists in OpenClaw versions prior to 2026.6.5 due to improper handling of HTTP redirects within the Model Context Protocol (MCP) Server-Sent Events (SSE) implementation. When a redirect occurs, the application fails to strip sensitive 'Authorization' headers before forwarding the request to the new destination. An attacker with low privileges who can influence the input path or reach the affected feature can capture these headers, leading to an exposure of sensitive information (CWE-200, CWE-522). The vulnerability is exploitable over the network without user interaction, provided the affected feature is enabled. The issue is resolved in version 2026.6.5.
Affected products
- OpenClaw OpenClaw before 2026.6.5
Timeline
- 2026-06-30: advisory: GitHub Security Advisory published
- 2026-07-17: disclosed: NVD publication date