CVE-2026-28477 - OpenClaw < 2026.2.14 - OAuth State Validation Bypass in Manual Chutes Login Flow
CVE ID : CVE-2026-28477
Published : March 5, 2026, 10:16 p.m. | 1 hour, 40 minutes ago
Description : OpenClaw versions prior to 2026.2.14 contain an oauth state validation bypass vulnerability in the manual Chutes login flow that allows attackers to bypass CSRF protection. An attacker can convince a user to paste attacker-controlled OAuth callback data, enabling credential substitution and token persistence for unauthorized accounts.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : March 5, 2026, 10:16 p.m. | 1 hour, 40 minutes ago
Description : OpenClaw versions prior to 2026.2.14 contain an oauth state validation bypass vulnerability in the manual Chutes login flow that allows attackers to bypass CSRF protection. An attacker can convince a user to paste attacker-controlled OAuth callback data, enabling credential substitution and token persistence for unauthorized accounts.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...