OpenClaw Redaction Bypass Vulnerability in SourceConfig and RuntimeConfig Aliases

Vulnerability

A redaction bypass vulnerability has been identified in OpenClaw versions prior to 2026.4.14. This vulnerability allows authenticated gateway clients with config read access to receive unredacted secrets through the sourceConfig and runtimeConfig alias fields. Exploitation of this vulnerability could lead to the disclosure of provider API keys, gateway authentication material, and channel credentials that were supposed to be redacted.

Impact

Exploitation of this vulnerability could result in the unauthorized disclosure of sensitive information, including API keys, authentication materials, and channel credentials.

Reproduction

To reproduce this vulnerability, an authenticated gateway client with config read access can request the sourceConfig and runtimeConfig alias fields. These fields will contain unredacted secrets that should have been redacted, such as provider API keys and gateway authentication materials.

Remediation

Users are advised to upgrade to OpenClaw version 2026.4.14 or later. The latest npm release, 2026.4.14, includes the necessary fix.

Added: May 5, 2026, 12:35 PM
Updated: May 5, 2026, 12:35 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.3
remediation
0.0
relevance
7.3
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.