#VU125085 Information disclosure in OpenClaw
Published: April 7, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to expose a PKCE verifier.
The vulnerability exists due to exposure of sensitive information in the macOS app beta onboarding OAuth flow when handling Anthropic OAuth sign-in. A remote attacker can obtain exposed OAuth state values together with OAuth authorization artifacts to expose a PKCE verifier.
The issue is limited to the macOS beta onboarding OAuth path and does not affect the core CLI or gateway onboarding paths.