CVE-2026-28481

MEDIUM

OpenClaw <2026.1.30 - Info Disclosure

Title source: llm
STIX 2.1

Description

OpenClaw versions 2026.1.30 and earlier, contain an information disclosure vulnerability, patched in 2026.2.1, in the MS Teams attachment downloader (optional extension must be enabled) that leaks bearer tokens to allowlisted suffix domains. When retrying downloads after receiving 401 or 403 responses, the application sends Authorization bearer tokens to untrusted hosts matching the permissive suffix-based allowlist, enabling token theft.

Scores

CVSS v3 6.5
EPSS 0.0004
EPSS Percentile 10.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-201
Status published
Products (2)
npm/openclaw 0 - 2026.2.1npm
openclaw/openclaw < 2026.1.30
Published Mar 05, 2026
Tracked Since Mar 06, 2026