Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q8cf-gmjr-64qh

Опубликовано: 17 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6
CVSS3: 6.5

Описание

OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot Framework tokens. Attackers can access configured input paths to retrieve credentials that should remain within the trusted boundary.

OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot Framework tokens. Attackers can access configured input paths to retrieve credentials that should remain within the trusted boundary.

EPSS

Процентиль: 17%
0.00258
Низкий

6 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 6.5
nvd
29 дней назад

OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot Framework tokens. Attackers can access configured input paths to retrieve credentials that should remain within the trusted boundary.

EPSS

Процентиль: 17%
0.00258
Низкий

6 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-522