mediumCVSS 5Vulnerability

GHSA-4mhr-cxr4-2prm

### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-h2vw-ph2c-jvwf. This link is maintained to preserve external references. ### Original Description OpenClaw versions 2026.4.5 before 2026.4.20 contain an environment variable injection vulnerability allowing workspace dotenv to override MINIMAX_API_HOST. Attackers can redirect credentialed MiniMax API requests to attacker-controlled origins, exposing the MiniMax API key in Authorization headers.

Properties

ghsa_id
GHSA-4mhr-cxr4-2prm
severity
medium
summary
Duplicate Advisory: OpenClaw: Workspace dotenv MiniMax host override could redirect credentialed requests
cvss_score
5
cve_id
GHSA-4mhr-cxr4-2prm
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
is_ghsa_only
true
ghsa_published
2026-05-11T18:31:46Z
source_url
https://github.com/advisories/GHSA-4mhr-cxr4-2prm
ghsa_updated
2026-05-18T15:30:30Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]npm/OpenClaw

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (1)

[Weakness]Unintended Proxy or Intermediary ('Confused Deputy')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-4mhr-cxr4-2prm (CVSS 5) — Ninja Signal Threat Intelligence | Ninja Signal