PT-2026-39681 · Openclaw · Openclaw
Nathan
·
Published
2026-04-25
·
Updated
2026-05-11
·
CVE-2026-44992
CVSS v4.0
6.8
Medium
| Vector | AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions 2026.4.5 through 2026.4.19
Description
An environment variable injection allows the workspace dotenv to override the
MINIMAX API HOST variable. This enables attackers to redirect credentialed MiniMax API requests to origins under their control, which exposes the MiniMax API key contained in the Authorization headers.Recommendations
Update to version 2026.4.20.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw