Executive brief
OpenClaw is an automation platform that integrates with messaging and communication services through various connectors (Matrix, Mattermost, IRC, Synology). A flaw in versions before 2026.4.22 allowed workspace configuration files to override the connector endpoint addresses, enabling an insider with workspace access to redirect traffic to attacker-controlled servers. This could lead to interception of communications, credential theft, or malware injection into the platform's message handling.
Technical details
The vulnerability is rooted in insufficient validation of environment variable overrides loaded from workspace-level .env files (CWE-441: Unintended Proxy or Intermediary). Workspace dotenv loading did not properly restrict endpoint configuration variables for Matrix homeserver, Mattermost base URL, IRC host, and Synology API endpoints. An attacker with write access to a workspace's configuration files could set these variables to redirect the connector runtime to malicious endpoints under their control. Attack requires local or workspace-level access and user interaction to execute affected connectors. The fix restricts endpoint variable overrides in workspace .env loading, while preserving trusted global runtime dotenv configuration. Patched in version 2026.4.22 (commit 0623079).
Affected products
- OpenClaw openclaw < 2026.4.22
Timeline
- 2026-04-23: disclosed
- 2026-04-23: patched: Fix released in version 2026.4.22
- 2026-05-11: advisory: GHSA-55cf-xx38-4p9p published (GHSA-5jgm-f9wr-9qm7 withdrawn as duplicate)
- 2026-05-18: other: GHSA-5jgm-f9wr-9qm7 withdrawn as duplicate of GHSA-55cf-xx38-4p9p
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-55cf-xx38-4p9p
- https://github.com/openclaw/openclaw/commit/0623079e98abf7202591f1b04a89755eb7ec9272
- https://github.com/openclaw/openclaw
- https://www.vulncheck.com/advisories/openclaw-connector-endpoint-host-override-via-workspace-dotenv-files