
CVE-2026-45005 OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to remain valid after rotation and reload. Attacker… https://www.cve.org/CVERecord?id=CVE-2026-45005
Post summary
The post announces CVE‑2026‑45005, detailing a secret‑management flaw that allows stale secrets to persist after rotation, but no PoC, exploitation, or patch is discussed.
