{"data":{"id":"c31a118a-d8e7-491f-b203-eeced438664b","title":"CVE-2026-100528: OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint. In ","summary":"OpenClaw (an npm package) before version 2026.8.1 had a bug where credentials (authentication information) for third-party API providers could be accidentally sent to the wrong endpoint (server address) if the model metadata didn't include a specific base URL and the session was still active after a configuration update. This could leak sensitive credentials to an unrelated provider and cause authentication failures. The issue is fixed in version 2026.8.1.","solution":"Update OpenClaw to version 2026.8.1 or later. Additionally, the source states that \"operators who observed this condition should rotate the affected credential\" (generate new authentication credentials to replace the ones that may have been exposed).","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-100528","publishedAt":"2026-09-26T03:16:58.057Z","cveId":"CVE-2026-100528","cweIds":["CWE-200"],"cvssScore":"5.4","cvssSeverity":"medium","severity":"medium","attackType":["pii_leakage"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["OpenAI"],"affectedVendorsRaw":["OpenAI","OpenClaw"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:L","attackVector":"network","attackComplexity":"high","privilegesRequired":"low","userInteraction":"required","exploitMaturity":"unknown","epssScore":0.00243,"patchAvailable":null,"disclosureDate":"2026-09-26T03:16:58.057Z","capecIds":["CAPEC-116"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}