Improper Input Validation in OpenClaw Bot Framework by OpenClaw
CVE-2026-62214
6MEDIUM
What is CVE-2026-62214?
The OpenClaw Bot Framework is susceptible to an improper input validation flaw in versions prior to 2026.5.28. This vulnerability permits lower-trust callers to potentially expose sensitive bot tokens and credentials due to inadequate validation of serviceUrl parameters. Malicious actors can inject harmful serviceUrl values via configured input paths, thereby gaining unauthorized access to confidential authentication data outside of established security boundaries. It is crucial for users to update to the latest version to mitigate these risks.
Affected Version(s)
msteams 0 < 2026.5.28
msteams 2026.5.28
