GHSA-q8cf-gmjr-64qhMediumCVSS 6.5

OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound...

Published
July 17, 2026
Last Modified
July 17, 2026

🔗 CVE IDs covered (1)

📋 Description

OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot Framework tokens. Attackers can access configured input paths to retrieve credentials that should remain within the trusted boundary.

🔗 References (4)