#VU125129 Incomplete List of Disallowed Inputs in OpenClaw - CVE-2026-32913
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to disclose sensitive authorization credentials.
The vulnerability exists due to an incomplete list of disallowed headers in fetchWithSsrFGuard(...) when following cross-origin redirects. A remote attacker can trigger a cross-origin redirect to disclose sensitive authorization credentials.
The issue affects custom authorization headers such as X-Api-Key and Private-Token that are preserved across an origin change.