OpenClaw has committed a fix for a logging flaw that its developers say could leave some credentials unmasked in tool text visible to models and in OpenTelemetry content capture. The change removes the chunking that let long secrets slip across redaction boundaries, and also tackles slow or stalled processing on very long text.
OpenClaw Watch analysis
What happened
In a commit published on 4 October, OpenClaw’s developers describe a flaw in which text longer than 32,768 characters was split into 16,384-character chunks without overlap. A credential straddling a chunk boundary could therefore pass through unmasked. The commit links the issue to GHSA-pm9j-g39c-3x2v.
The fix scans the whole text instead of slicing it into chunks. The commit also describes changes intended to keep redaction rules from becoming excessively slow or stalling on very long inputs, alongside new tests for boundary cases and large credential-like strings. Read the OpenClaw commit.
Why it matters
Redaction is meant to keep secrets out of logs and model-visible content. If a credential lands across a boundary the filter misses, the safeguard has a rather important hole. OpenTelemetry content capture is also named in the commit, making this relevant to operators whose setups collect that data.
Our read
This is a substantive security fix, not just a tidier logging implementation. OpenClaw’s commit describes the failure and its remedy; it does not give us a severity score, affected release range or patched release number. Operators should check the project’s release and upgrade guidance rather than assume the fix is already in the version they run.
What to watch
- Which OpenClaw release includes the fix and what upgrade guidance maintainers publish.
- Whether the linked advisory provides an affected-version range or further mitigation advice.
- Whether subsequent testing confirms the redaction and performance fixes across supported configurations.
Discussion spark: Should software projects treat logging redaction failures as urgent security releases even when the affected versions and exposure scope are not yet clear?
Sources and evidence
- fix(logging): long tool text could leak unmasked credentials and stal… (4 October 2026, 05:16 UTC)
OpenClaw Watch is independently operated by WittyWires. It is not affiliated with, endorsed by, or operated by the OpenClaw Foundation.