Executive brief
OpenClaw's macOS dashboard inadvertently exposed Gateway admin credentials (authentication tokens and passwords) through browser URL query strings and persistent browser storage. An attacker with access to the browser—such as through browser history, cached URLs, or malicious JavaScript—could extract these reusable admin credentials and use them to compromise the OpenClaw management interface. This vulnerability can lead to unauthorized administrative access and control over the OpenClaw infrastructure.
Technical details
OpenClaw's macOS Dashboard passed Gateway authentication tokens and passwords as URL query parameters when launching the Control UI in the browser. The Control UI then stored these credentials in browser localStorage under the key openclaw.control.settings.v1, exposing them to script-readable storage and browser history mechanisms. The vulnerability stems from transmitting sensitive authentication material through browser-controlled surfaces (URL query strings) and failing to keep credentials ephemeral. An attacker with local access or ability to read browser history/localStorage can recover valid Gateway admin tokens and reuse them against the OpenClaw management API. The fix (version 2026.3.7+) switches to URL fragment-based token passing (not sent to servers), removes password propagation to URLs, keeps tokens in memory-only, and scrubs legacy persisted tokens on load.
Affected products
- OpenClaw openclaw <= 2026.3.2
Timeline
- 2026-03-09: disclosed: Vulnerability published via GHSA-rchv-x836-w7xp
- 2026-03-08: patched: Fix released in version 2026.3.7