Information disclosure in OpenClaw - #VU125085
Published: April 7, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to expose a PKCE verifier.
The vulnerability exists due to exposure of sensitive information in the macOS app beta onboarding OAuth flow when handling Anthropic OAuth sign-in. A remote attacker can obtain exposed OAuth state values together with OAuth authorization artifacts to expose a PKCE verifier.
The issue is limited to the macOS beta onboarding OAuth path and does not affect the core CLI or gateway onboarding paths.