Incomplete Comparison with Missing Factors in OpenClaw - #VU132719
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to incomplete comparison with missing factors in the trusted retry endpoint validation logic when processing a retry endpoint URL chosen by lower-trust input. A remote user can supply a hostname-prefixed endpoint URL to disclose sensitive information.
Only instances where the affected feature is enabled and reachable are vulnerable.