CVE-2026-34511: Openclaw

Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.

OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it through the redirect URL. Attackers who capture the redirect URL can obtain both the authorization code and PKCE verifier, defeating PKCE protection and enabling token redemption.

Affected products

  • Openclaw Openclaw: before 2026.4.2 (fixed in 2026.4.2)

Published 2026-04-03. Last modified 2026-07-24.