Vulnerability Description
OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it through the redirect URL. Attackers who capture the redirect URL can obtain both the authorization code and PKCE verifier, defeating PKCE protection and enabling token redemption.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openclaw | Openclaw | < 2026.4.2 |
Related Weaknesses (CWE)
References
- https://github.com/openclaw/openclaw/commit/a26f4d0f3ef0757db6c6c40277cc06a5de76Patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-9jpj-g8vv-j5mfVendor Advisory
- https://www.vulncheck.com/advisories/openclaw-pkce-verifier-exposure-via-oauth-sThird Party Advisory
FAQ
What is CVE-2026-34511?
CVE-2026-34511 is a vulnerability with a CVSS score of 5.3 (MEDIUM). OpenClaw before 2026.4.2 reuses the PKCE verifier as the OAuth state parameter in the Gemini OAuth flow, exposing it through the redirect URL. Attackers who capture the redirect URL can obtain both th...
How severe is CVE-2026-34511?
CVE-2026-34511 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-34511?
Check the references section above for vendor advisories and patch information. Affected products include: Openclaw Openclaw.