CVE-2026-62213

Severity CVSS v4.0:
MEDIUM
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
17/07/2026
Last modified:
21/07/2026

Description

OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot Framework tokens. Attackers can access configured input paths to retrieve credentials that should remain within the trusted boundary.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* 2026.5.27 (excluding)