Workspace Dotenv File Vulnerability in OpenClaw for Matrix, Mattermost, IRC, and Synology
CVE-2026-45003
4.1MEDIUM
What is CVE-2026-45003?
The OpenClaw platform prior to version 2026.4.22 contains a flaw that allows workspace dotenv files to override connector endpoint hosts. This vulnerability enables attackers with access to a workspace to alter traffic by manipulating endpoint variables defined in dotenv files, potentially redirecting runtime requests to malicious endpoints. The issue affects connectors for popular services like Matrix, Mattermost, IRC, and Synology, posing significant risks to data integrity and application security.
Affected Version(s)
OpenClaw 0 < 2026.4.22
OpenClaw 2026.4.22
