Description
OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint. In affected versions, when a third-party provider uses an OpenAI-compatible API and the resolved model metadata lacks a concrete base URL, a pinned session that continues after a model configuration hot reload retains that provider's credential while the OpenAI SDK selects its own default endpoint. A resulting request could disclose the configured third-party provider credential to an unrelated provider endpoint and fail with a misleading authentication error. Operators who observed this condition should rotate the affected credential. The issue is fixed in 2026.8.1.
Published: 2026-09-26
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Credential Disclosure
Action: Patch
AI Analysis

Impact

The vulnerability arises when OpenClaw, before version 2026.8.1, sends third‑party provider credentials to the wrong endpoint. In affected builds, a provider that uses an OpenAI‑compatible API and whose resolved model metadata lacks a concrete base URL can cause a pinned session to retain that provider’s credential after a model configuration hot reload. Because the OpenAI SDK selects its own default endpoint, a request may be sent to an unrelated provider endpoint. This results in the disclosure of the third‑party provider’s credential and a misleading authentication error. The flaw is a credential disclosure weakness (CWE‑200).

Affected Systems

The issue affects the OpenClaw npm package (openclaw) on all releases prior to version 2026.8.1. Users deploying these earlier versions are susceptible to leaking the credentials of any third‑party provider configured within the package.

Risk and Exploitability

The vulnerability carries a CVSS score of 5.9, indicating a moderate severity. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog. The likely attack vector requires that an attacker can influence the provider configuration or model metadata or can observe the misdirected API traffic; the exploit could enable them to capture credentials for a third‑party provider. No public exploit has been reported, so the risk depends primarily on the presence of vulnerable versions and whether credentials are exposed.

Generated by OpenCVE AI on September 26, 2026 at 03:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the OpenClaw package to version 2026.8.1 or later.
  • If an upgrade is not immediately possible, rotate any third‑party provider credentials that are currently configured.
  • Ensure that all provider configurations used with OpenAI‑compatible APIs include a concrete base URL to prevent misrouting of requests.

Generated by OpenCVE AI on September 26, 2026 at 03:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 26 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Description OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint. In affected versions, when a third-party provider uses an OpenAI-compatible API and the resolved model metadata lacks a concrete base URL, a pinned session that continues after a model configuration hot reload retains that provider's credential while the OpenAI SDK selects its own default endpoint. A resulting request could disclose the configured third-party provider credential to an unrelated provider endpoint and fail with a misleading authentication error. Operators who observed this condition should rotate the affected credential. The issue is fixed in 2026.8.1.
Title OpenClaw before 2026.8.1 Credential Disclosure via Provider Endpoint
First Time appeared Openclaw
Openclaw openclaw
Weaknesses CWE-200
CPEs cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:*:*:*
Vendors & Products Openclaw
Openclaw openclaw
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:L'}

cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Openclaw Openclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-26T02:18:30.427Z

Reserved: 2026-09-26T01:00:40.148Z

Link: CVE-2026-100528

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-26T03:16:58.057

Modified: 2026-09-26T03:16:58.057

Link: CVE-2026-100528

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-26T05:15:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor