OpenClaw before 2026.4.14 contains a redaction bypass vulnerability that allows authenticated gateway clients to receive unredacted secrets through sourceConfig and runtimeConfig alias fields. Attackers with config read access can exploit this to obtain provider API keys, gateway authentication material, and channel credentials that should have been redacted.
References
Configurations
History
07 May 2026, 01:54
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/openclaw/openclaw/commit/86734ef93a2f25063371b04f1946eb300548acd4 - Patch | |
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-8372-7vhw-cm6q - Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-redaction-bypass-via-sourceconfig-and-runtimeconfig-aliases - Third Party Advisory | |
| First Time |
Openclaw
Openclaw openclaw |
|
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
05 May 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-05 12:16
Updated : 2026-05-07 01:54
NVD link : CVE-2026-43528
Mitre link : CVE-2026-43528
CVE.ORG link : CVE-2026-43528
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
