Junglewise Threat Intelligence

OpenClaw information disclosure via custom header leakage in MCP redirects

Severity: high · CVSS 7.1 · Published 2026-06-16

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a tool used for managing Model Context Protocol (MCP) servers, contains a flaw that can leak sensitive information. When connecting to a remote server, the software may incorrectly send private security headers—such as API keys or login credentials—to an unauthorized third party if the server issues a redirect. This could allow a malicious or compromised server to steal credentials used for other services, potentially leading to unauthorized access to sensitive data or accounts.

Technical details

OpenClaw before version 2026.5.12 is vulnerable to sensitive information disclosure in its 'streamable-http' MCP server implementation. The root cause is the improper handling of HTTP redirects, where operator-configured custom headers (such as those containing API keys or tenant-routing credentials) are forwarded to the new origin during a cross-origin redirect. An attacker who controls or compromises an MCP endpoint can trigger a redirect to an attacker-controlled server to exfiltrate these headers. This vulnerability requires the attacker to have control over an MCP endpoint configured within the system. The issue is resolved in version 2026.5.12.

Affected products

  • OpenClaw openclaw < 2026.5.12

Timeline

  • 2026-05-28: advisory: Original advisory GHSA-rjxq-qqhf-8hwh published
  • 2026-06-16: disclosed: CVE-2026-53840 published to NVD
  • 2026-06-17: other: Duplicate advisory GHSA-x7cf-6gp3-q5f8 withdrawn

References