PT-2026-49043 · Openclaw · Openclaw
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.5.7
Description
An issue exists in the retry endpoint checks where hostname validation allows matching hostname prefixes instead of requiring exact hostnames. This allows attackers to craft a hostname prefix that resembles a trusted host, potentially leading to the transmission of authentication material to untrusted endpoints.
Recommendations
Update to version 2026.5.7.
Exploit
Fix
Insufficient Verification of Data Authenticity
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw