
Cloud Vulnerability DB
A community-led vulnerabilities database
OpenClaw's macOS Dashboard flow exposed Gateway authentication material to browser-controlled surfaces.
Before the fix, the macOS app appended the shared Gateway token and password to the Dashboard URL query string when opening the Control UI in the browser. The Control UI then imported the token and persisted it into browser localStorage under openclaw.control.settings.v1.
This expanded exposure of reusable Gateway admin credentials into browser address-bar/query surfaces and persistent script-readable storage.
openclaw (npm)2026.3.2<= 2026.3.2>= 2026.3.7An attacker with access to browser-controlled surfaces or persistent browser storage could recover a valid Gateway admin token and reuse it against the OpenClaw management interface. The exposure chain was:
Open Dashboard constructed a URL with auth material.localStorage.The fix aligns the macOS Dashboard flow with the safer existing CLI/bootstrap pattern and removes persistent browser token storage:
openclaw.control.settings.v1 on load.10d0e3f3ca92326df0ca071fabffe463742f263c (March 7, 2026)npm 2026.3.7 was published on March 8, 2026. This advisory is fixed in the released package.
Thanks @whiter6666 for reporting.
Source: NVD
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."