VYPR
Medium severity5.0NVD Advisory· Published May 11, 2026· Updated May 13, 2026

CVE-2026-44992

CVE-2026-44992

Description

OpenClaw versions 2026.4.5 before 2026.4.20 contain an environment variable injection vulnerability allowing workspace dotenv to override MINIMAX_API_HOST. Attackers can redirect credentialed MiniMax API requests to attacker-controlled origins, exposing the MiniMax API key in Authorization headers.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
openclawnpm
>= 2026.4.5, < 2026.4.202026.4.20

Affected products

3
  • OpenClaw/Openclawreferences3 versions
    (expand)+ 2 more
    • (no CPE)
    • cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*range: >=2026.4.5,<2026.4.20
    • (no CPE)range: >=2026.4.5 <2026.4.20

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.