CVE-2026-100528

CVE-2026-100528 published: OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint. In affected versions, when a third-party provider uses an OpenAI-compatible API and the resolved model metadata lacks a concrete base URL, a...

View full NVD advisory → ← Back to CVE watch