Executive brief
OpenClaw is an AI gateway tool. A vulnerability in its message forwarding feature could allow sensitive credentials and data to be sent to an unauthorized local address. This could result in the exposure of authentication tokens to other users or processes on the same system.
Technical details
A vulnerability exists in OpenClaw's message.action forwarding mechanism where model-controlled action metadata can specify a loopback Gateway URL. When this occurs, the system may forward the action payload along with Gateway credentials (tokens) to a local listener chosen by the attacker. This is classified as insufficient protection of credentials (CWE-522). Exploitation requires the affected feature to be enabled and reachable by lower-trust input. The issue is addressed in version 2026.5.2.
Affected products
- OpenClaw openclaw <= 2026.4.29
Timeline
- 2026-05-28: disclosed
- 2026-07-02: advisory
- 2026-05-02: patched: First stable patched version 2026.5.2 released around May/June 2026 based on versioning.