Executive brief
OpenClaw, a tool used for managing gateway operations and plugins, contains a flaw in how it handles server-sent event (SSE) redirects. This vulnerability could allow sensitive login credentials to be sent to unauthorized locations, potentially allowing an attacker to perform actions as a legitimate user. Organizations should upgrade to the latest version to prevent unauthorized access to their gateway management systems.
Technical details
OpenClaw is vulnerable to sensitive information exposure and open redirection within its Model Context Protocol (MCP) Server-Sent Events (SSE) implementation. The root cause is the improper handling of HTTP redirects, which causes the application to forward 'Authorization' headers to the redirect target. An attacker with low privileges can leverage this to capture credentials or session tokens if they can control the redirect destination or if a lower-trust input path is reachable. This could lead to unauthorized action execution or persistence. The issue is addressed in version 2026.6.5.
Affected products
- OpenClaw openclaw < 2026.6.5
Timeline
- 2026-06-30: disclosed
- 2026-07-01: advisory
- 2026-06-30: patched: First stable patched version 2026.6.5 released.
References
- https://api.github.com/users/dingliweixlm-byte
- https://github.com/dingliweixlm-byte
- https://api.github.com/users/dingliweixlm-byte/gists%7B/gist_id%7D
- https://api.github.com/users/dingliweixlm-byte/repos
- https://avatars.githubusercontent.com/u/269614575?v=4
- https://api.github.com/users/dingliweixlm-byte/events%7B/privacy%7D