CVE-2026-59261: OpenClaw < 2026.5.28 - Credential Override via Workspace Dotenv Files

Published Jul 8, 2026
·
Updated

OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with lower-trust access to configured input paths can expose sensitive data and credentials that should remain within trusted boundaries.

Affected Software

2 affected components
OpenClaw OpenClaw<2026.5.28
OpenClaw Openclaw Node.js<2026.5.28

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenClaw to a version that resolves this vulnerability.

    Fixed in 2026.5.28
  2. Compensating control

    Ensure attackers do not have lower-trust access to configured input paths that allow modification of workspace dotenv files, so provider credentials cannot be overridden via those dotenv files.

Event History

Jul 8, 2026
CVE Published
via MITRE·04:01 PM
Data Sourced
via MITRE·04:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-59261?

CVE-2026-59261 has a severity rating of 8.4, which is classified as high.

2

How do I fix CVE-2026-59261?

To resolve CVE-2026-59261, upgrade OpenClaw to version 2026.5.28 or later.

3

What vulnerability does CVE-2026-59261 describe?

CVE-2026-59261 describes a credential exposure vulnerability that allows workspace dotenv files to override provider credentials.

4

Who is impacted by CVE-2026-59261?

Users of OpenClaw versions prior to 2026.5.28 are at risk due to this vulnerability.

5

What can attackers do with CVE-2026-59261?

Attackers with low-trust access can exploit this vulnerability to expose sensitive data and credentials.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203