Medium severity6.5NVD Advisory· Published Jul 17, 2026· Updated Jul 21, 2026
CVE-2026-62213
CVE-2026-62213
Description
OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot Framework tokens. Attackers can access configured input paths to retrieve credentials that should remain within the trusted boundary.
Affected products
2Patches
Vulnerability mechanics
References
2- github.com/openclaw/openclaw/security/advisories/GHSA-v54h-q2vx-vgg4nvdMitigationVendor Advisory
- www.vulncheck.com/advisories/openclaw-token-leakage-via-ms-teams-outbound-requestsnvdThird Party Advisory
News mentions
0No linked articles in our index yet.