CVE-2026-34511
OpenClaw < 2026.4.2 - PKCE Verifier Exposure via OAuth State Parameter
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
03 Apr 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it through the redirect URL. Attackers who capture the redirect URL can obtain both the authorization code and PKCE verifier, defeating PKCE protection and enabling token redemption.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
OpenClaw · OpenClawWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →