Information Disclosure Vulnerability in OpenClaw by OpenClaw
CVE-2026-53840
6MEDIUM
What is CVE-2026-53840?
OpenClaw versions prior to 2026.5.12 are vulnerable to an information disclosure issue affecting streamable HTTP MCP servers. This vulnerability allows attackers with control over an MCP endpoint to execute cross-origin redirects, potentially exfiltrating sensitive operator-configured custom headers, such as API keys and tenant-routing credentials, to unauthorized origins. Properly securing these headers is crucial to prevent sensitive data leakage and mitigate risks associated with unauthorized access.
Affected Version(s)
OpenClaw 0 < 2026.5.12
OpenClaw 2026.5.12
