medium · CVSS v3 5.4 · CVSS v4 5.9 · EPSS 0.00243
CVE-2026-100528
OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint. In …
Description
OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint. In affected versions, when a third-party provider uses an OpenAI-compatible API and the resolved model metadata lacks a concrete base URL, a pinned session that continues after a model configuration hot reload retains that provider's credential while the OpenAI SDK selects its own default endpoint. A resulting request could disclose the configured third-party provider credential to an unrelated provider endpoint and fail with a misleading authentication error. Operators who observed this condition should rotate the affected credential. The issue is fixed in 2026.8.1.
Scores
- Severity
- medium
- CVSS v2
- 5.6
- CVSS v3
- 5.4
- CVSS v4
- 5.9
- EPSS
- 0.00243