Junglewise Threat Intelligence

CVE-2026-41398: OpenClaw: iOS A2UI bridge trusted generic local-network pages for agent.request dispatch

CVE-2026-41398 · Severity: medium · CVSS 4 · Published 2026-04-07

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an AI automation platform with iOS support. A flaw in the iOS version allowed untrusted web pages loaded from local networks to dispatch commands to the active AI session without proper authorization, potentially draining compute budget and corrupting session state through injected requests.

Technical details

The vulnerability is an insufficient origin-validation bug (CWE-284) in the iOS A2UI bridge component. Before version 2026.4.2, generic local-network or tailnet pages loaded via canvas.navigate or canvas.present were trusted implicitly and could call agent.request dispatch without passing the stricter trusted-canvas origin check required for remote canvas URLs. An attacker-controlled page loaded from a local-network or tailnet host could trigger unauthorized agent.request execution, polluting AI session state and consuming budget. The fix restricts A2UI bridge trust to the bundled scaffold and exact capability-backed remote URLs only, eliminating the open trust of generic local-network origins. No evidence of exploitation in the wild has been reported, and the demonstrated impact excludes owner-only actions or arbitrary host execution.

Affected products

  • OpenClaw openclaw <= 2026.4.1

Timeline

  • 2026-04-07: disclosed
  • 2026-04-02: patched: Fix commit 49d08382a90f71dabe2877b3f6729ad85f808d57 authored; staged for release 2026.4.2

References