OpenClaw: CLI Remote Onboarding Persists Unauthenticated Discovery Endpoint and Exfiltrates Gateway Credentials
Description
Published to the GitHub Advisory Database
Mar 31, 2026
Reviewed
Mar 31, 2026
Last updated
May 8, 2026
Summary
Remote onboarding accepted discovered gateway endpoints without an explicit trust confirmation before persisting the remote URL and connection details.
Impact
A malicious or spoofed discovery endpoint could steer onboarding toward an attacker-controlled gateway and capture future gateway credentials or traffic.
Affected Component
src/commands/onboard-remote.tsFixed Versions
<= 2026.3.24>= 2026.3.282026.3.28contains the fix.Fix
Fixed by commit
d6affb17d8(CLI: confirm discovered remote gateways before saving config).References