CVE-2026-32982: OpenClaw < 2026.3.13 - Telegram Bot Token Exposure in Media Fetch Error Logs
Published Mar 31, 2026
·Updated
OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes Telegram bot tokens in error messages. When media downloads fail, the original Telegram file URLs containing bot tokens are embedded in MediaFetchError strings and leaked to logs and error surfaces.
Affected Software
2 affected components
OpenClaw<2026.3.13
OpenClaw Openclaw Node.js<2026.3.13
Remediation
Event History
Mar 31, 2026
CVE Published
via MITRE·11:17 AM
Data Sourced
via MITRE·11:17 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-32982?
CVE-2026-32982 is categorized as an information disclosure vulnerability due to the exposure of Telegram bot tokens in error logs.
2
How do I fix CVE-2026-32982?
To fix CVE-2026-32982, upgrade OpenClaw to version 2026.3.13 or later.
3
What specific function is affected in CVE-2026-32982?
The fetchRemoteMedia function in OpenClaw is affected by CVE-2026-32982.
4
What information is exposed by CVE-2026-32982?
CVE-2026-32982 exposes Telegram bot tokens in error messages when media downloads fail.
5
Which versions of OpenClaw are vulnerable to CVE-2026-32982?
OpenClaw versions prior to 2026.3.13 are vulnerable to CVE-2026-32982.