OpenClaw Credential Exposure Vulnerability via Cross-Origin Redirects in Media Download

Vulnerability

A credential exposure vulnerability has been identified in OpenClaw versions prior to 2026.3.31. This vulnerability arises in the media download functionality, where Authorization headers are forwarded across cross-origin redirects. Attackers can exploit this by creating malicious cross-origin redirect chains to intercept sensitive authorization credentials meant for legitimate requests.

Impact

Exploitation of this vulnerability leads to unauthorized interception of authorization credentials, creating a risk of credential leakage.

Reproduction

To reproduce this vulnerability, save a media file from a cross-origin source while including an Authorization header. The request will forward the Authorization header across cross-origin redirects, potentially exposing the credential to an interceptor.

Remediation

Users can update to OpenClaw version 2026.3.31 or later, where this vulnerability has been patched.

Added: Apr 23, 2026, 10:32 PM
Updated: Apr 23, 2026, 10:32 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.7
remediation
0.0
relevance
6.5
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.