Executive brief
OpenClaw, a tool used for managing AI-related workspaces, contains a vulnerability that allows a malicious workspace configuration to redirect sensitive requests. If a user opens a compromised workspace, their MiniMax API credentials could be sent to a server controlled by an attacker. This could lead to the theft of API keys and unauthorized use of paid AI services.
Technical details
An environment variable injection vulnerability exists in OpenClaw's handling of workspace-specific .env files. By placing a malicious .env file in a workspace, an attacker can override the MINIMAX_API_HOST variable. When a user runs OpenClaw within that workspace, credentialed requests intended for the MiniMax API are redirected to an attacker-controlled origin. This results in the exposure of the MiniMax API key via the outbound Authorization header. The issue is classified as a 'Confused Deputy' (CWE-441) vulnerability and has been patched in version 2026.4.20 by blocking the override of critical host variables.
Affected products
- OpenClaw openclaw >= 2026.4.5, < 2026.4.20
Timeline
- 2026-04-21: advisory: Original advisory GHSA-h2vw-ph2c-jvwf published
- 2026-05-11: disclosed: CVE-2026-44992 published
- 2026-05-18: patched: Duplicate advisory GHSA-4mhr-cxr4-2prm withdrawn in favor of original