Improper access control in OpenClaw - #VU126841
Published: April 22, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the MiniMax request path when loading environment variables from a workspace .env file. A remote user can supply a crafted workspace .env that overrides MINIMAX_API_HOST to disclose sensitive information.
Exploitation requires running OpenClaw from an attacker-controlled workspace.