PT-2026-23552 · Openclaw · Openclaw

Aether Ai

·

Published

2026-02-18

·

Updated

2026-03-07

·

CVE-2026-28477

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.14
Description The manual Chutes OAuth login flow in OpenClaw is susceptible to a bypass of OAuth CSRF state validation. This allows an attacker to bypass CSRF protection by convincing a user to paste attacker-controlled OAuth callback data, potentially leading to credential substitution and the persistence of tokens for unauthorized accounts. The automatic local callback flow is not affected.
Recommendations Update to version 2026.2.14 or later.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2026-28477
GHSA-7RCP-MXPQ-72PJ

Affected Products

Openclaw