---
id: CVE-2026-59261
title: OpenClaw < 2026.5.28 - Credential Override via Workspace Dotenv Files
summary: >-
  OpenClaw before 2026.5.28 contains a credential exposure vulnerability where
  workspace dotenv files can override provider credentials. Attackers with
  lower-trust access to configured input paths can expose sensitive data and
  credentials …
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'
cvssSource: cna
cwe:
  - CWE-184
vendor: OpenClaw
product: OpenClaw
affected:
  - OpenClaw < 2026.5.28
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-07-08T00:00:00+00:00'
published: '2026-07-08'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T14:17:55.584Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-59261'
references:
  - url: >-
      https://github.com/openclaw/openclaw/security/advisories/GHSA-4pqj-3c56-5fqq
    label: GitHub Security Advisory (GHSA-4pqj-3c56-5fqq)
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-credential-override-via-workspace-dotenv-files
tags:
  - cve.org
epss: 0.00273
epssPercentile: 0.19984
ingestedAt: '2026-09-24T15:45:56.726Z'
---

## Overview

OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with lower-trust access to configured input paths can expose sensitive data and credentials that should remain within trusted boundaries.

## Affected

- `OpenClaw < 2026.5.28`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
