Executive brief
OpenClaw, a tool used for managing workspace connectors, contains a vulnerability where local configuration files (.env) can be used to redirect network traffic. An attacker with access to a workspace could modify these files to force the application to send data to a malicious server instead of the intended service (such as Matrix, Mattermost, or IRC). This could lead to the exposure of sensitive communication data or credentials.
Technical details
OpenClaw before version 2026.4.22 is vulnerable to a 'Confused Deputy' or uncontrolled resource reference flaw (CWE-441/CWE-610). The application incorrectly allows workspace-specific .env files to override global connector endpoint configurations for Matrix, Mattermost, IRC, and Synology connectors. An attacker with local workspace access can define malicious endpoint variables in a .env file. When the runtime loads these configurations, traffic is redirected to the attacker-controlled host, potentially allowing for the interception of sensitive data. The fix implements a blocklist for these specific endpoint variables during workspace-level dotenv loading.
Affected products
- OpenClaw openclaw <= 2026.4.21
Timeline
- 2026-04-23: advisory: Original advisory GHSA-55cf-xx38-4p9p published
- 2026-05-11: advisory: Duplicate advisory GHSA-5jgm-f9wr-9qm7 published and CVE-2026-45003 assigned
- 2026-05-18: other: Duplicate advisory GHSA-5jgm-f9wr-9qm7 withdrawn in favor of GHSA-55cf-xx38-4p9p