PT-2026-26746 · Openclaw · Openclaw
Aether Ai
·
Publicado
2026-03-03
·
Atualizado
2026-05-18
·
CVE-2026-32897
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.2.22
Description
The software reuses the
gateway.auth.token as a fallback hash secret for owner-ID prompt obfuscation when commands.ownerDisplay is set to hash and commands.ownerDisplaySecret is unset. This creates a dual-use of authentication secrets across security domains. An attacker with access to system prompts sent to third-party model providers can derive the gateway authentication token from the hash outputs, potentially compromising gateway authentication security.Recommendations
Update to version 2026.2.22 or later.
Correção
Insufficiently Protected Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Openclaw