Executive brief
mf-yang openclaw-cn is a community-maintained AI assistant platform that includes a browser control API for automating web interactions. A security flaw in this API allows an authorized user to bypass network restrictions and force the automated browser to access internal or private websites that should be blocked. This could allow an attacker to view sensitive internal data, access local administrative dashboards, or probe the private corporate network from the server hosting the application.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the Browser Control HTTP API of openclaw-cn. While the application implements an SSRF policy (`browser.ssrfPolicy.allowPrivateNetwork=false`) for direct navigation via the `/navigate` route, it fails to enforce this policy when navigation is triggered through user interactions. Specifically, the `clickViaPlaywright` function in `src/browser/routes/agent.act.ts` does not validate the destination URL after a click action. An authenticated attacker can load a benign page containing a link to a loopback or private IP address, use the `/act` route to click that link, and then use the `/snapshot` route to read the content of the restricted internal resource. As of the advisory date, no patch is available.
Affected products
- mf-yang openclaw-cn <= 0.2.1
Timeline
- 2026-07-26: advisory: Public disclosure of CVE-2026-17458