MEDIUM 5.9 NVD
CVE-2026-100528
OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint. In affected versions, when a third-party pr
OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint. In affected versions, when a third-party provider uses an OpenAI-compatible API and the resolved model metadata lacks a concrete base URL, a pinned session that continues after a model configuration hot reload retains that provider's credential while the OpenAI SDK selects its own default endpoint. A resulting request could disclose the configured third-party provider credential to an unrelated provider endpoint and fail with a misleading authentication error. Operators who observed this condition should rotate the affected credential. The issue is fixed in 2026.8.1.
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-vhpg-cq3w-v8p9
- https://www.vulncheck.com/advisories/openclaw-before-2026.8.1-credential-disclosure-via-pr
This medium severity vulnerability with a CVSS score of 5.9 was published on 2026-09-26 via NVD.
vulnfeed aggregates 11591 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.