CVE-2026-45003

MEDIUM

OpenClaw < 2026.4.22 - Connector Endpoint Host Override via Workspace dotenv Files

Title source: cna
STIX 2.1

Description

OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC, and Synology connectors. Attackers with workspace access can redirect runtime traffic to malicious endpoints by setting endpoint variables in dotenv files.

References (3)

Core 3
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-55cf-xx38-4p9p)
https://github.com/openclaw/openclaw/security/advisories/GHSA-55cf-xx38-4p9p
Third Party Advisory third-party-advisory
VulnCheck Advisory: OpenClaw < 2026.4.22 - Connector Endpoint Host Override via Workspace dotenv Files
https://www.vulncheck.com/advisories/openclaw-connector-endpoint-host-override-via-workspace-dotenv-files

Scores

CVSS v3 5.0
EPSS 0.0001
EPSS Percentile 1.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-441
Status published
Products (4)
npm/openclaw 0 - 2026.4.22npm
OpenClaw/OpenClaw < 2026.4.22
openclaw/openclaw < 2026.4.22
OpenClaw/OpenClaw 2026.4.22
Published May 11, 2026
Tracked Since May 11, 2026