CVE-2026-100528: Openclaw

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint. In affected versions, when a third-party provider uses an OpenAI-compatible API and the resolved model metadata lacks a concrete base URL, a pinned session that continues after a model configuration hot reload retains that provider's credential while the OpenAI SDK selects its own default endpoint. A resulting request could disclose the configured third-party provider credential to an unrelated provider endpoint and fail with a misleading authentication error. Operators who observed this condition should rotate the affected credential. The issue is fixed in 2026.8.1.

Affected products

  • Openclaw Openclaw: before 2026.8.1 (fixed in 2026.8.1)

Published 2026-09-26. Last modified 2026-09-30.