Vulnerabilities
Report: Update: CVE-2026-43528 - OpenClaw < 2026.4.14 - Redaction Bypass via sourceConfig and runtimeConfig Aliases
CVE ID :CVE-2026-43528 Published : May 5, 2026, 11:24 a.m. | 57 minutes ago Description :OpenClaw before 2026.4.14 contains a redaction bypass vulnerability that allows authenticated gateway clients to receive unredacted secrets through sourceConfig and runtimeConfig alias fields. Attackers with config read access can exploit this to obtain provider API keys, gateway authentication material, and channel credentials that should have been redacted. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...