Information disclosure in OpenClaw - CVE-2026-35644
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information in gateway snapshot fields when returning data from config.get and channels.status. A remote user can read credential-bearing baseUrl and related endpoint fields to disclose sensitive information.
The issue affects read-scoped gateway snapshots and exposes credentials embedded in URL userinfo fields.