Impact
OpenClaw before 2026.5.28 contains a credential exposure vulnerability (CWE‑184) where workspace dotenv files can override provider credentials. This flaw can be triggered when an attacker has lower‑trust access to the configured input paths, enabling the reading or manipulation of files that store sensitive configuration. Consequently, credentials that should remain within trusted boundaries can be exposed or replaced, potentially giving the attacker unauthorized access to dependent services or data.
Affected Systems
The affected product is OpenClaw. Versions earlier than 2026.5.28 are susceptible to this credential override flaw. All releases of OpenClaw from 2026.5.28 onward include the vendor‑supplied fix described in the advisory.
Risk and Exploitability
The CVSS score of 8.4 classifies the issue as high severity, indicating a significant impact if exploited. The EPSS score of <1% suggests that exploitation is currently rare in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The attack could be carried out by an entity that has lower‑trust or local access to the workspace input path, such as an attacker with limited file‑system permissions, who could place a malicious dotenv file to override credentials. No confirmed remote exploitation is reported, so a local or privilege‑Escalation vector is inferred.
OpenCVE Enrichment