CVE-2026-27003: Openclaw

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

OpenClaw is a personal AI assistant. Telegram bot tokens can appear in error messages and stack traces (for example, when request URLs include `https://api.telegram.org/bot<token>/...`). Prior to version 2026.2.15, OpenClaw logged these strings without redaction, which could leak the bot token into logs, crash reports, CI output, or support bundles. Disclosure of a Telegram bot token allows an attacker to impersonate the bot and take over Bot API access. Users should upgrade to version 2026.2.15 to obtain a fix and rotate the Telegram bot token if it may have been exposed.

Affected products

  • Openclaw Openclaw: before 2026.2.15 (fixed in 2026.2.15)

Published 2026-02-20. Last modified 2026-06-17.