Executive brief
OpenClaw is a browser automation and testing framework that uses Chrome's debugging protocol. A vulnerability allows a local attacker on the same machine to intercept authentication tokens by listening on loopback network connections, potentially granting unauthorized access to the OpenClaw Gateway service. This risk applies primarily to shared-host deployments where untrusted local users can run processes on the same system.
Technical details
The vulnerability is an information disclosure flaw (CWE-290, CWE-306) in OpenClaw's Chrome Debug Protocol (CDP) relay implementation. When OpenClaw performs CDP reachability probes to loopback URLs, it injects the x-openclaw-relay-token authentication header. An attacker controlling a loopback port can intercept these probes sent to /json/version, capture the token, and reuse it as a Gateway bearer token for unauthorized API access. The attack requires local code execution and assumes the attacker can race or bind an available loopback port. Fix is available in version 2026.2.22 or later.
Affected products
- OpenClaw openclaw <= 2026.2.21-2
Timeline
- 2026-03-03: disclosed
- 2026-02-23: patched: Fix commit afa22acc4a09fdf32be8a167ae216bee85c30dad; patched version >= 2026.2.22