Unrated severityNVD Advisory· Published Jul 17, 2026· Updated Jul 20, 2026
OpenClaw < 2026.5.27 Token Leakage via MS Teams Outbound Requests
CVE-2026-62213
Description
OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot Framework tokens. Attackers can access configured input paths to retrieve credentials that should remain within the trusted boundary.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/openclaw/openclaw/security/advisories/GHSA-v54h-q2vx-vgg4mitrevendor-advisory
- www.vulncheck.com/advisories/openclaw-token-leakage-via-ms-teams-outbound-requestsmitrethird-party-advisory
News mentions
0No linked articles in our index yet.