Executive brief
OpenClaw is an AI-powered local assistant that performs automated tasks across operating systems and platforms. A vulnerability allows attackers to bypass browser-based security checks that prevent Server-Side Request Forgery (SSRF) attacks by triggering navigation through user interactions, potentially enabling unauthorized access to internal resources or services that should be restricted.
Technical details
This vulnerability is a Server-Side Request Forgery (SSRF) policy bypass (CWE-918) in OpenClaw's browser navigation handling. The root cause is that browser interactions can trigger navigations that circumvent normal SSRF protection checks. The attack requires local user interaction to trigger the malicious navigation—there is no network vector; this is a local privilege or trust model violation within OpenClaw's user-controlled execution model. An attacker with interactive access can bypass SSRF restrictions to navigate to and potentially exfiltrate data from internal systems or services. The vulnerability affects versions up to 2026.4.5 and is fixed in version 2026.4.8, with patch commit d7c3210cd6f5fdfdc1beff4c9541673e814354d5 verified against regression tests.
Affected products
- OpenClaw OpenClaw ≤ 2026.4.5
Timeline
- 2026-04-09: disclosed
- 2026-04-08: patched: Fix available in version 2026.4.8