CVE-2026-45003

MEDIUM EPSS 1.3%
Published May 11, 20261mo ago · Modified Jun 17, 20261w ago
4.1 CVSS 4.0
Medium
Find Similar
Published May 11, 2026 1mo ago
Last Modified Jun 17, 2026 1w ago

Description

OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC, and Synology connectors. Attackers with workspace access can redirect runtime traffic to malicious endpoints by setting endpoint variables in dotenv files.

CVSS Details

Base Score
4.1
Exploitability
Impact
Vector string
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction P
Scope X

Threat Intelligence

EPSS Exploit Probability
1.3% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-441

Affected Products 1

VendorProductVersionRange
openclawopenclaw* <2026.4.22

References 3

  • github.com https://github.com/openclaw/openclaw/commit/0623079e98abf7202591f1b04a89755eb7ec9272
    Patch
  • github.com https://github.com/openclaw/openclaw/security/advisories/GHSA-55cf-xx38-4p9p
    Third Party Advisory
  • vulncheck.com https://www.vulncheck.com/advisories/openclaw-connector-endpoint-host-override-via-workspace-dotenv-files
    PatchThird Party Advisory

Remediation

  • github.com https://github.com/openclaw/openclaw/commit/0623079e98abf7202591f1b04a89755eb7ec9272
    Patch
  • vulncheck.com https://www.vulncheck.com/advisories/openclaw-connector-endpoint-host-override-via-workspace-dotenv-files
    PatchThird Party Advisory