#VU125154 Information disclosure in OpenClaw - CVE-2026-33575
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information in pairing setup codes generated by /pair and openclaw qr when embedding setup payloads. A remote attacker can obtain a leaked setup code to disclose sensitive information.
Leaked codes may be exposed through chat history, logs, screenshots, or copied QR payloads.