OpenClaw WebSocket Gateway Credential Transmission Vulnerability

Vulnerability

A vulnerability in OpenClaw versions prior to 2026.4.2 allows for the transmission of stored gateway credentials over unencrypted WebSocket connections. The issue arises because the application accepts non-loopback cleartext 'ws://' gateway endpoints. This flaw can be exploited by forging discovery results or crafting setup codes to redirect clients to malicious endpoints, where plaintext gateway credentials can be intercepted.

Impact

Exploitation of this vulnerability could lead to the unauthorized disclosure of gateway credentials to an attacker-controlled endpoint.

Reproduction

To reproduce this vulnerability, first connect to a non-loopback cleartext 'ws://' gateway endpoint using the OpenClaw application on Android. This can be done by either forging a discovery result or scanning a crafted setup code that directs the application to the malicious endpoint. Once the connection is established, the stored gateway credentials will be transmitted in plaintext over the unencrypted WebSocket connection.

Remediation

Users can update to OpenClaw version 2026.4.2 or later, which addresses this vulnerability by requiring TLS for remote gateway endpoints.

Added: Apr 21, 2026, 12:30 AM
Updated: Apr 21, 2026, 12:30 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.5
remediation
0.0
relevance
6.4
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.