OpenClaw Dotenv File Override Vulnerability for Connector Endpoints

Vulnerability

A vulnerability in OpenClaw versions prior to 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC, and Synology connectors. This issue enables attackers with workspace access to redirect runtime traffic to malicious endpoints by specifying endpoint variables in dotenv files.

Impact

Exploitation of this vulnerability could lead to unauthorized redirection of connector traffic to malicious endpoints, potentially causing misuse of the application's integration with these services.

Reproduction

The vulnerability can be reproduced by creating a workspace dotenv file that includes specific endpoint variables for Matrix, Mattermost, IRC, or Synology connectors. Once these variables are set, the application will redirect traffic intended for the original endpoints to the ones specified in the dotenv file. This can be verified by checking the application's traffic or logs to see if it has been redirected to the malicious endpoints.

Remediation

Users can update to OpenClaw version 2026.4.22 or later, where this vulnerability has been fixed.

Added: May 11, 2026, 7:02 PM
Updated: May 11, 2026, 7:02 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.3
remediation
0.0
relevance
8.0
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.