---
id: CVE-2026-62214
title: >-
  OpenClaw versions before 2026.5.28 Bot Framework contains an improper input
  validation vulnerability that allows lower-trust callers to expose bot tokens
  and credentials by failing to properly validate serviceUrl parameters
summary: >-
  OpenClaw versions before 2026.5.28 Bot Framework contains an improper input
  validation vulnerability that allows lower-trust callers to expose bot tokens
  and credentials by failing to properly validate serviceUrl parameters.
  Attackers ca…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-522
vendor: openclaw
product: openclaw
affected:
  - openclaw < 2026.5.28
patched:
  - openclaw 2026.5.28
published: '2026-07-17'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:26.470'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-62214'
references:
  - url: >-
      https://github.com/openclaw/openclaw/security/advisories/GHSA-prwc-c6w5-mmgr
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-bot-framework-ssrf-via-serviceurl-parameter-validation
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-07-17T10:40:17.454600Z'
epss: 0.0044
epssPercentile: 0.36227
ingestedAt: '2026-10-08T16:52:14.701Z'
---

## Overview

OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-trust callers to expose bot tokens and credentials by failing to properly validate serviceUrl parameters. Attackers can supply malicious serviceUrl values through configured input paths to retrieve sensitive authentication data outside the trusted boundary.

## Affected

- `openclaw < 2026.5.28`

## Remediation

Upgrade past the affected range:

- `openclaw 2026.5.28`
