Impact
The vulnerability arises when OpenClaw, before version 2026.8.1, sends third‑party provider credentials to the wrong endpoint. In affected builds, a provider that uses an OpenAI‑compatible API and whose resolved model metadata lacks a concrete base URL can cause a pinned session to retain that provider’s credential after a model configuration hot reload. Because the OpenAI SDK selects its own default endpoint, a request may be sent to an unrelated provider endpoint. This results in the disclosure of the third‑party provider’s credential and a misleading authentication error. The flaw is a credential disclosure weakness (CWE‑200).
Affected Systems
The issue affects the OpenClaw npm package (openclaw) on all releases prior to version 2026.8.1. Users deploying these earlier versions are susceptible to leaking the credentials of any third‑party provider configured within the package.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.9, indicating a moderate severity. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog. The likely attack vector requires that an attacker can influence the provider configuration or model metadata or can observe the misdirected API traffic; the exploit could enable them to capture credentials for a third‑party provider. No public exploit has been reported, so the risk depends primarily on the presence of vulnerable versions and whether credentials are exposed.
OpenCVE Enrichment