Junglewise Threat Intelligence

CVE-2026-17457: mf-yang openclaw-cn local file disclosure in Scheme Handler

CVE-2026-17457 · Severity: medium · CVSS 4.3 · Published 2026-07-26

Executive brief

A security flaw in the openclaw-cn AI assistant platform allows authenticated users to access sensitive local files on the server. By bypassing navigation restrictions, an attacker can force the application's internal browser to open and display local system files, such as configuration data or temporary logs. This could lead to the exposure of private information to unauthorized parties.

Technical details

A local file disclosure vulnerability exists in the `assertBrowserNavigationAllowed` function within `src/browser/navigation-guard.ts`. The navigation guard only validates `http:` and `https:` protocols, returning early for any other scheme without performing security checks. An authenticated attacker can exploit this by sending a `POST` request to the `/tabs/open` endpoint with a `file://` URL. The application then uses the Chrome DevTools Protocol (CDP) to open the local file, allowing the attacker to retrieve the file's contents via the `/snapshot` endpoint. As of the advisory date, the project has not responded to the issue report.

Affected products

  • mf-yang openclaw-cn up to 0.2.1

Timeline

  • 2026-07-26: advisory: Vulnerability published by VulDB/NVD
  • 2026-07-26: disclosed: Public exploit details released via GitHub issue

References

Related threats