Executive brief
OpenClaw is an automation platform that includes a sandboxed browser feature for controlled web interactions. The sandbox browser's local HTTP bridge server was running without authentication, allowing any process on the same machine to enumerate tabs, execute JavaScript in page contexts, and steal session cookies and data from authenticated browser sessions.
Technical details
The vulnerability is a missing authentication check (CWE-306) in the sandbox browser bridge server initialization path. When the sandboxed browser feature is enabled, OpenClaw starts a local loopback HTTP server exposing browser control endpoints (/profiles, /tabs, /tabs/open, /agent/*, and Chrome DevTools Protocol WebSocket URLs). Due to missing auth wiring, this bridge server accepted all requests without requiring the gateway authentication token/password that loopback clients should use. Attack vector is local-only (CVSS AV:L); an attacker must have code execution on the same machine. An attacker can enumerate open tabs, open/close/navigate tabs, execute arbitrary JavaScript via CDP, and exfiltrate cookies and session data. The fix (v2026.2.14) enforces authentication on the bridge server, restricts binding to loopback only, and adds regression tests.
Affected products
- OpenClaw OpenClaw >=2026.1.29-beta.1, <2026.2.14
Timeline
- 2026-02-18: disclosed: Advisory GHSA-h9g4-589h-68xv published
- 2026-02-14: patched: Fix committed; patch released in v2026.2.14