OpenClaw Exposes Credentials Embedded in baseUrl Fields via config.get and channels.status
Moderate severity
GitHub Reviewed
Published
Mar 24, 2026
in
openclaw/openclaw
•
Updated Mar 26, 2026
Description
Published to the GitHub Advisory Database
Mar 26, 2026
Reviewed
Mar 26, 2026
Last updated
Mar 26, 2026
Summary
Read-scoped gateway snapshots could expose credentials embedded in channel baseUrl and related endpoint fields.
Affected Packages / Versions
openclaw(npm)v2026.3.23-2(630f1479c44f78484dfa21bb407cbe6f171dac87)2026.3.23-2Fix Commit(s)
f0202264d0de7ad345382b9008c5963bcefb01b7Release Status
The fix shipped in
v2026.3.22and remains present inv2026.3.23andv2026.3.23-2.Code-Level Confirmation
OpenClaw thanks @zpbrent for reporting.
References