{"id":"CVE-2026-53840","aliases":["GHSA-rjxq-qqhf-8hwh"],"url":"https://o3.security/vulnerability/CVE-2026-53840","summary":"OpenClaw < 2026.5.12 - Custom Header Leakage via MCP Streamable HTTP Cross-Origin Redirects","details":"### Summary\n\nOpenClaw supports remote MCP Streamable HTTP servers with operator-configured custom headers. In affected releases, those headers could be forwarded when the MCP endpoint responded with a cross-origin redirect.\n\nThis issue is limited to configured MCP Streamable HTTP servers that use custom headers. It does not expose unrelated OpenClaw credentials.\n\n### Affected configurations\n\nThis affects deployments where an MCP server is configured with:\n\n- `transportType: \"streamable-http\"`\n- sensitive custom headers under `mcp.servers.*.headers`\n- an MCP endpoint that is malicious, compromised, or able to redirect to another origin\n\n### Impact\n\nCustom MCP headers, such as API keys or tenant-routing headers, could be sent to the redirect target. The exposed credential scope depends on the header the operator configured for that MCP server.\n\n### Patched Versions\n\nThe first stable patched version is `2026.5.12`.\n\n### Mitigations\n\nUpgrade to `openclaw@2026.5.8` or later. Before upgrading, avoid custom MCP headers with servers you do not fully trust, and rotate any MCP-specific credentials that may have been exposed by a redirecting endpoint.","published":"2026-06-16T18:04:53.345Z","modified":"2026-08-17T03:55:02.617460774Z","cvss":null,"epss":{"score":0.00223,"percentile":0.12788,"asOf":"2026-09-01"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"openclaw","fixedVersion":"2026.5.12"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53840.json"},{"type":"ADVISORY","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-rjxq-qqhf-8hwh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53840"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/openclaw-custom-header-leakage-via-mcp-streamable-http-cross-origin-redirects"},{"type":"PACKAGE","url":"https://github.com/openclaw/openclaw"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-17T03:55:02.617460774Z"}}