CVE-2026-43528

OpenClaw before 2026.4.14 contains a redaction bypass vulnerability that allows authenticated gateway clients to receive unredacted secrets through sourceConfig and runtimeConfig alias fields. Attackers with config read access can exploit this to obtain provider API keys, gateway authentication material, and channel credentials that should have been redacted.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

07 May 2026, 01:54

Type Values Removed Values Added
References () https://github.com/openclaw/openclaw/commit/86734ef93a2f25063371b04f1946eb300548acd4 - () https://github.com/openclaw/openclaw/commit/86734ef93a2f25063371b04f1946eb300548acd4 - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-8372-7vhw-cm6q - () https://github.com/openclaw/openclaw/security/advisories/GHSA-8372-7vhw-cm6q - Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-redaction-bypass-via-sourceconfig-and-runtimeconfig-aliases - () https://www.vulncheck.com/advisories/openclaw-redaction-bypass-via-sourceconfig-and-runtimeconfig-aliases - Third Party Advisory
First Time Openclaw
Openclaw openclaw
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

05 May 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-05 12:16

Updated : 2026-05-07 01:54


NVD link : CVE-2026-43528

Mitre link : CVE-2026-43528

CVE.ORG link : CVE-2026-43528


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-212

Improper Removal of Sensitive Information Before Storage or Transfer