Cross-site request forgery in OpenClaw - CVE-2026-28477
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to substitute credentials for another account.
The vulnerability exists due to insufficient OAuth state validation in the manual Chutes OAuth login flow when processing user-supplied OAuth callback data. A remote attacker can provide crafted callback input to substitute credentials for another account.
User interaction is required to paste attacker-provided OAuth callback data during the manual login prompt. The automatic local callback flow is not affected.