Junglewise Threat Intelligence

CVE-2026-42436: OpenClaw browser snapshot and screenshot SSRF bypass

CVE-2026-42436 · Severity: low · CVSS 3.1 · Published 2026-04-17

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a browser automation tool used to take snapshots, screenshots, and control browser tabs. The vulnerability allows authenticated users to bypass SSRF (Server-Side Request Forgery) protections and access internal pages that should be restricted, by navigating the browser to a forbidden URL and then capturing its content before validation occurs.

Technical details

The vulnerability is a Server-Side Request Forgery (SSRF) bypass in the browser snapshot, screenshot, and tab routes. The root cause is insufficient validation of the final browser target after navigation—the routes did not consistently re-check whether the loaded page complies with the configured SSRF policy before returning content. An authenticated attacker can trigger navigation to an internal or restricted URL and immediately capture a snapshot or screenshot before the policy validation logic re-executes, exposing content from disallowed hosts. The fix (v2026.4.14) adds explicit re-validation of the final browser state against the SSRF policy and includes regression test coverage for these routes.

Affected products

  • OpenClaw openclaw < 2026.4.14

Timeline

  • 2026-04-17: disclosed
  • 2026-04-17: patched: v2026.4.14 released

References

Related threats