Junglewise Threat Intelligence

CVE-2026-35673: OpenClaw SSRF policy bypass in browser debug and export routes

CVE-2026-35673 · Severity: medium · CVSS 6.5 · Published 2026-05-29

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a tool used for browser-based automation and data export, contains a security flaw in its debugging and export features. An attacker with low-level access could bypass internal network protections to view or export sensitive data from browser tabs that should have been blocked. This could lead to the unauthorized exposure of private internal web content or administrative interfaces.

Technical details

A Server-Side Request Forgery (SSRF) policy bypass exists in OpenClaw's browser debug and export routes. The vulnerability occurs because the application fails to re-apply security policies when a caller references and reuses an already-open browser tab that was previously blocked by private-network SSRF policies. An authenticated attacker with network access to these specific routes can exploit this behavior to inspect or export content from protected internal resources. Exploitation requires the 'affected feature' to be enabled and typically involves some level of user interaction or specific session state where a blocked tab remains open. The issue is addressed in version 2026.4.29 by ensuring policies are correctly enforced during tab reuse.

Affected products

  • OpenClaw OpenClaw < 2026.4.29

Timeline

  • 2026-05-28: advisory: GitHub Security Advisory published
  • 2026-05-29: disclosed: NVD publication date
  • 2026-04-29: patched: First stable patched version released

References

Related threats