Description
OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that forwards operator-configured custom headers during cross-origin redirects. Attackers controlling or compromising an MCP endpoint can redirect requests to exfiltrate sensitive headers like API keys or tenant-routing credentials to attacker-controlled origins.
Problem types
Insufficiently Protected Credentials
Product status
Any version before 2026.5.12
2026.5.12 (semver)
Credits
Edward-x (@YLChen-007)
References
github.com/...enclaw/security/advisories/GHSA-rjxq-qqhf-8hwh (GitHub Security Advisory (GHSA-rjxq-qqhf-8hwh))
www.vulncheck.com/...-streamable-http-cross-origin-redirects (VulnCheck Advisory: OpenClaw < 2026.5.12 - Custom Header Leakage via MCP Streamable HTTP Cross-Origin Redirects)