PT-2026-30235 · Openclaw · Openclaw
Raax
·
Published
2026-04-03
·
Updated
2026-04-04
·
CVE-2026-34511
CVSS v4.0
7.0
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.4.2
Description
The application reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it through the redirect URL. An attacker capturing the redirect URL can obtain both the authorization code and PKCE verifier, defeating PKCE protection and enabling token redemption.
Recommendations
Update to version 2026.4.2 or later.
Fix
Insufficient Verification of Data Authenticity
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw