CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-53840

CVE-2026-53840: Sensitive Header Leakage via Cross-Origin Redirects in OpenClaw MCP Servers

Alon Barad
Alon Barad
Software Engineer

Jun 17, 2026·7 min read·8 visits

Executive Summary (TL;DR)

OpenClaw versions prior to 2026.5.12 leak configured custom HTTP headers to third-party domains when an MCP server returns a redirect response. Attackers can leverage this behavior to capture sensitive API keys and tokens.

An information disclosure vulnerability exists in OpenClaw before version 2026.5.12. The issue resides within the streamable-http Model Context Protocol (MCP) server integration, where the application client automatically forwards operator-configured custom headers during cross-origin HTTP redirects. If an attacker controls or compromises a configured remote MCP endpoint, they can issue redirect responses to exfiltrate highly sensitive data, such as API keys or tenant-routing credentials, to unauthorized external origins.

Vulnerability Overview

OpenClaw leverages Model Context Protocol (MCP) servers to coordinate and orchestrate remote execution environments. A principal method for this communication is the streamable-http transport layer. This layer allows system operators to configure custom HTTP headers, such as credentials, tenant identifiers, and cryptographic keys, ensuring proper routing and authentication. These parameters are stored in the application's configuration under the mcp.servers.*.headers block.

When a request is initiated from OpenClaw to a remote MCP server, the underlying HTTP client automatically appends these custom headers to the outbound request envelope. However, the client is configured to follow HTTP redirection instructions natively. In versions of OpenClaw prior to 2026.5.12, the transport layer did not assess whether the destination target specified in a redirect response matched the original host origin.

This behavior exposes a cross-origin credential leakage vulnerability classified under CWE-522 (Insufficiently Protected Credentials). The primary attack surface exists anywhere an operator integrates an external, untrusted, or multi-tenant streamable-http MCP server with custom authentication configurations. By failing to strip headers during origin shifts, the software allows unauthorized third parties to capture active credentials.

Root Cause Analysis

The root cause of CVE-2026-53840 is an operational deficiency in the HTTP redirect validation logic of the OpenClaw client-side streamable-http transport layer. In Node.js environments, standard HTTP clients such as Axios or native Fetch API configurations may follow HTTP status codes in the 3xx range (such as 301, 302, 307, or 308) automatically. When doing so, they often carry forward the initial request headers to the new destination.

To prevent information disclosure, security specifications require that HTTP clients perform an origin comparison check prior to dispatching redirected requests. Specifically, if the protocol, hostname, or port of the target redirect URL deviates from the initial destination, any custom or authorization headers must be purged. The OpenClaw client failed to execute this check, resulting in the preservation of custom-configured headers across distinct HTTP origins.

This flaw is especially critical because the headers defined in mcp.servers are frequently high-value secrets, such as API keys or bearer tokens. The vulnerability does not leak the global administrative credentials of the OpenClaw application itself. Instead, it exposes the custom-defined credentials linked to the compromised or malicious streamable-http configuration.

Code Analysis

To understand the implementation flaw, consider the representative JavaScript/TypeScript code path managing MCP connections. Prior to the patch, the application initialized HTTP requests using standard fetch parameters where automatic redirection was permitted without interceptor logic.

// Vulnerable Implementation (Before 2026.5.12)
async function fetchMcpData(mcpConfig: McpConfig, endpoint: string) {
  const targetUrl = new URL(endpoint, mcpConfig.baseUrl);
  const response = await fetch(targetUrl.toString(), {
    method: 'GET',
    headers: {
      ...mcpConfig.headers, // Includes sensitive custom API tokens
      'Accept': 'application/json'
    },
    redirect: 'follow' // Automatically follows redirects retaining all headers
  });
  return response.json();
}

The configuration redirect: 'follow' delegates redirectional control entirely to the runtime's engine, which does not perform cross-origin sanitization on custom header properties. To remedy this flaw in version 2026.5.12, the development team updated the client to manage redirections manually. By changing the redirection strategy to manual, the client intercepts the redirect, inspects the target origin, and sanitizes the headers prior to initiating the subsequent call.

// Patched Implementation (In 2026.5.12)
async function fetchMcpDataPatched(mcpConfig: McpConfig, endpoint: string) {
  const initialUrl = new URL(endpoint, mcpConfig.baseUrl);
  let currentUrl = initialUrl;
  let headers = { ...mcpConfig.headers, 'Accept': 'application/json' };
  
  let response = await fetch(currentUrl.toString(), {
    method: 'GET',
    headers: headers,
    redirect: 'manual' // Handle redirections explicitly
  });
 
  if ([301, 302, 303, 307, 308].includes(response.status)) {
    const location = response.headers.get('location');
    if (location) {
      const redirectUrl = new URL(location, currentUrl);
      
      // Enforce cross-origin validation check
      if (redirectUrl.origin !== initialUrl.origin) {
        // Strip sensitive credentials on origin mismatch
        for (const sensitiveHeader of Object.keys(headers)) {
          if (isSensitiveHeader(sensitiveHeader)) {
            delete headers[sensitiveHeader];
          }
        } 
      }
      
      response = await fetch(redirectUrl.toString(), {
        method: 'GET',
        headers: headers,
        redirect: 'manual'
      });
    }
  }
  return response.json();
}
 
function isSensitiveHeader(headerName: string): boolean {
  const normalized = headerName.toLowerCase();
  const sensitivePatterns = ['auth', 'token', 'key', 'cookie', 'x-tenant'];
  return sensitivePatterns.some(pattern => normalized.includes(pattern));
}

Exploitation Methodology

Exploitation of CVE-2026-53840 requires a pre-existing trust configuration within the target OpenClaw system. The administrator must have registered a remote streamable-http MCP server that utilizes custom headers. The attacker must either directly control this registered MCP endpoint or successfully compromise it to intercept and manipulate its HTTP responses.

When OpenClaw makes an automated outbound API call to the configured MCP endpoint, the attacker's server responds with an HTTP redirect status code, such as 302 Found. The response includes a Location header pointing to an external destination under the attacker's administrative control. Because of the client-side flaw, OpenClaw follows this instruction and transmits the initial custom header set directly to the attacker's server.

The credential capture is silent and automated. Once the attacker extracts the token from the incoming headers on their listener server, they gain unauthorized access to the third-party service or routing gateway that the credentials were originally configured to authenticate against.

Impact Assessment

The potential consequences of CVE-2026-53840 depend entirely on the scope and privilege of the credentials stored within the mcp.servers configuration. Because these custom headers typically authenticate requests to remote execution environments, compromise of these credentials could lead to unauthorized API access, data exposure, or lateral movement within the connected systems.

CVSS 4.0 rates this vulnerability with a base score of 6.0 (Medium), reflecting a network attack vector with low complexity. The primary requirement is the configuration of an affected remote server. While the integrity and availability of the OpenClaw service itself are not directly degraded, the confidentiality impact on the targeted external secrets is high.

No public proof-of-concept exploits exist, and the vulnerability is not currently cataloged in the CISA Known Exploited Vulnerabilities registry. However, because credential theft represents a reliable technique for initial access and persistence, organizations employing streamable-http MCP instances should prioritize remediation to avoid potential key leakage.

Remediation & Detection

The definitive remediation for CVE-2026-53840 is upgrading the OpenClaw installation to version 2026.5.12 or newer. If immediate patching is not possible, operators using versions 2026.5.8 or higher can utilize early security adjustments implemented in those intermediary releases. This mitigates the immediate risks associated with automatic redirection forwarding.

In addition to upgrading, system administrators should conduct a comprehensive audit of all remote MCP connections configured under mcp.servers. Any custom headers used in conjunction with streamable-http configurations prior to the patch must be treated as potentially compromised. These credentials must be rotated immediately to invalidate any keys that may have been leaked.

Detection can be accomplished by analyzing outbound network traffic from the OpenClaw environment. Security teams should monitor for HTTP 3xx redirection responses originating from internal or external MCP endpoints that resolve to third-party domains. Any outbound request following a redirect that retains Authorization or custom headers should be flagged as an indicator of exposure.

Technical Appendix

CVSS Score
6.0/ 10
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS Probability
0.22%
Top 87% most exploited

Affected Systems

OpenClaw instances utilizing streamable-http Model Context Protocol servers configured with custom headers.

Affected Versions Detail

Product
Affected Versions
Fixed Version
openclaw
OpenClaw
< 2026.5.122026.5.12
AttributeDetail
CWE IDCWE-522: Insufficiently Protected Credentials
Attack VectorNetwork
CVSS v4.0 Base Score6.0 (Medium)
CVSS v3.1 Base Score6.8 (Medium)
EPSS Score0.00223 (Percentile: 12.73%)
Exploit StatusNo public PoCs available
CISA KEV StatusNot listed

MITRE ATT&CK Mapping

T1552Unsecured Credentials
Credential Access
CWE-522
Insufficiently Protected Credentials

The application transmits or stores sensitive credentials without sufficient protective measures, in this case, sending them to untrusted external origins over standard redirect mechanisms.

Vulnerability Timeline

Vulnerability published on CVE.org
2026-06-16
Verified NOT present in CISA KEV catalog
2026-06-16
GitHub Security Advisory GHSA-rjxq-qqhf-8hwh published and updated
2026-06-17
EPSS score analyzed and tracked
2026-06-17

References & Sources

  • [1]GitHub Security Advisory GHSA-rjxq-qqhf-8hwh
  • [2]VulnCheck Security Advisory
  • [3]OpenClaw Project Repository
  • [4]NVD CVE-2026-53840 Portal

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 6 hours ago•CVE-2026-5038
5.3

CVE-2026-5038: Denial of Service via Incomplete File Cleanup in Multer diskStorage Engine

CVE-2026-5038 is a critical denial of service vulnerability in the Node.js Multer middleware. When utilizing the diskStorage engine, connection termination or validation failures leave partial files orphaned on the local filesystem due to stream-destruction signal propagation failures in Node's piping mechanism. Remote unauthenticated attackers can exploit this to fill server disks and induce system crashes.

Amit Schendel
Amit Schendel
4 views•7 min read
•about 6 hours ago•CVE-2026-5079
7.5

CVE-2026-5079: Denial of Service via Uncontrolled Resource Consumption in Multer Multipart Parser

CVE-2026-5079 is a high-severity Denial of Service (DoS) vulnerability in the Node.js package 'multer'. The vulnerability resides in how its internal dependency, 'append-field', processes deeply nested bracket structures in multipart form field names. If an attacker submits a field name with an excessive number of nested brackets, the parsing process crashes the Node.js runtime environment or exhausts system resources, causing a complete denial of service.

Amit Schendel
Amit Schendel
7 views•6 min read
•about 7 hours ago•CVE-2026-9595
5.3

CVE-2026-9595: WebSocket Proxying Vulnerability in webpack-dev-server leading to Host/Origin Validation Bypass

webpack-dev-server (WDS) is vulnerable to an Origin Validation Error (CWE-346) and a Confused Deputy vulnerability (CWE-441) due to path normalization discrepancies in its upgrade handling. When a proxy is configured with a broad context and WebSocket support is enabled, the proxy middleware intercepts internal Hot Module Replacement (HMR) WebSocket upgrade requests. This forwards the browser's credentials (such as Cookies and Origin headers) to the backend target, bypassing built-in security controls and corrupting the WebSocket connection.

Amit Schendel
Amit Schendel
8 views•7 min read
•about 11 hours ago•GHSA-8JR5-V98P-W75M
8.6

GHSA-8JR5-V98P-W75M: Perception Desynchronization via Unnormalized EXIF Orientation and PNG Transparency in vLLM

A critical preprocessing mismatch exists in vLLM's multimodal image pipeline before commit cf1c90672404548aa3bc51f92c4745576a65ee26. The vulnerability occurs because the engine loads user-submitted images and passes them to underlying Vision-Language Models (VLMs) without normalizing their EXIF orientation metadata or fully resolving complex transparency structures. This gap creates a perception desynchronization vulnerability where the physical pixel grid processed by the AI model differs significantly from how the image is visually rendered to human moderators or frontend applications. Attackers can exploit this mismatch to perform silent prompt injections, bypass safety moderation systems, or execute adversarial jailbreaks.

Alon Barad
Alon Barad
3 views•8 min read
•about 12 hours ago•GHSA-664H-GPGQ-H6XX
5.4

GHSA-664h-gpgq-h6xx: Privilege Escalation via Broken Authorization in n8n Evaluation Test Runs Controller

An incorrect authorization vulnerability exists in the open-source workflow automation platform n8n within the Evaluation Test Runs Controller. In deployments utilizing Advanced Permissions, an authenticated user assigned a low-privilege project:viewer role can bypass configured permission policies. This allows the unauthorized user to execute, terminate, or delete workflow evaluation test runs by exploiting misconfigured API scope validations that map read-only scopes to mutating endpoints.

Amit Schendel
Amit Schendel
7 views•6 min read
•about 19 hours ago•GHSA-JWM3-QCFW-C5PP
5.1

GHSA-jwm3-qcfw-c5pp: Security Bypass in n8n Python Code Node AST Validator

An authenticated security-bypass vulnerability in n8n allows users with workflow creation or modification privileges to bypass the Python AST security validator. By circumventing AST validation logic, attackers can execute arbitrary statements, access the task executor's root module namespace, and disclose sensitive host environment variables on self-hosted instances.

Amit Schendel
Amit Schendel
8 views•6 min read