
Cloud Vulnerability DB
A community-led vulnerabilities database
The affected surface is the OpenClaw macOS app onboarding flow, and the macOS app is currently in beta.
In that beta onboarding flow, Anthropic OAuth used the PKCE code_verifier value as OAuth state, exposing that secret in front-channel URL state.
openclaw (npm)<= 2026.2.24 (latest published npm at triage time)apps/macos)2026.2.25Scope is limited to the macOS beta onboarding OAuth path. Exploitation required obtaining both OAuth authorization artifacts and exposed state values during that flow.
OpenClaw removed Anthropic OAuth sign-in from macOS onboarding and now supports setup-token-only Anthropic subscription auth in this path.
8f3310000a8b0c11eced054c2cdb6fb27803511apatched_versions is pre-set to the release (2026.2.25).
Advisory published with npm release 2026.2.25.2.25` is published, this advisory is published.
OpenClaw thanks @zdi-disclosures for reporting.
Source: NVD
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."