Junglewise Threat Intelligence

CVE-2026-41372: OpenClaw loopback protection bypass in CDP discovery

CVE-2026-41372 · Severity: medium · CVSS 5.8 · Published 2026-04-28

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a tool used for browser automation and control. A security flaw in how it handles network discovery allows an attacker to bypass safety protections and redirect the software to interact with the local computer instead of the intended remote target. This could allow an attacker to gain unauthorized access to browser data or internal services running on the user's machine.

Technical details

OpenClaw versions prior to 2026.4.2 contain a loopback protection bypass in the Chrome DevTools Protocol (CDP) discovery mechanism. The software fails to properly normalize hostnames that use an absolute form (e.g., 'localhost.') in discovery responses. An attacker can provide a malicious discovery response that uses this trailing-dot notation to circumvent security checks intended to prevent remote profiles from pivoting to the local loopback interface. This allows the attacker to retarget authenticated browser control toward localhost endpoints, potentially exposing sensitive browser state or internal services. The issue is fixed in version 2026.4.2.

Affected products

  • OpenClaw OpenClaw < 2026.4.2

Timeline

  • 2026-04-02: advisory: Vendor advisory GHSA-fh32-73r9-rgh5 published
  • 2026-04-27: disclosed: CVE-2026-41372 published
  • 2026-04-28: patched: Version 2026.4.2 released

References

Related threats