HIGH
OpenClaw < 2026.3.13 - Telegram Bot Token Exposure in Media Fetch Error Logs
Published Mar 31, 2026
8.7
HIGHCVSS 4.0
EPSS 0.51%
Description
OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes Telegram bot tokens in error messages. When media downloads fail, the original Telegram file URLs containing bot tokens are embedded in MediaFetchError strings and leaked to logs and error surfaces.
Affected products
-
- Version 0StatusaffectedConstraints<2026.3.13
- Version 2026.3.13StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.3.13
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.3.13 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-17385 Advisory
- https://github.com/openclaw/openclaw/commit/7a53eb7ea8295b08be137e231c9a98c1a79b5cd5 patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-xwcj-hwhf-h378 vendor-advisoryVendor Advisory
- https://www.vulncheck.com/advisories/openclaw-telegram-bot-token-exposure-in-media-fetch-error-logs third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-17385 | Advisory | |
| https://github.com/openclaw/openclaw/commit/7a53eb7ea8295b08be137e231c9a98c1a79b5cd5 | patch | |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-xwcj-hwhf-h378 | vendor-advisoryVendor Advisory | |
| https://www.vulncheck.com/advisories/openclaw-telegram-bot-token-exposure-in-media-fetch-error-logs | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Mar 31, 2026
Updated Jun 23, 2026
Reserved Mar 17, 2026
Link CVE-2026-32982
CISA Vulnrichment
Updated Apr 2, 2026
ENISA EUVD
EUVD-2026-17385 Assigner VulnCheck
Published Mar 31, 2026
Updated Jun 23, 2026
Exploited since n/a
Link EUVD-2026-17385