Executive brief
OpenClaw is a JavaScript library for browser automation and tab management. The /tabs/action select and close endpoints failed to enforce Server-Side Request Forgery (SSRF) policies, allowing attackers with authentication to navigate browser tabs to arbitrary URLs that should have been blocked, potentially exposing internal services or resources.
Technical details
OpenClaw's browser tab management API includes /tabs/action endpoints for selecting and closing tabs. These endpoints failed to enforce configured SSRF policies, allowing authenticated users to bypass intended navigation restrictions. An attacker with valid credentials to the OpenClaw service could direct browser tabs to restricted internal URLs (e.g., localhost services, cloud metadata endpoints) that should have been blocked by SSRF policy enforcement, leading to information disclosure. The vulnerability was fixed in version 2026.4.10 by adding SSRF policy validation to the affected tab-action routes (PR #63332, commit 48c0347).
Affected products
- OpenClaw openclaw < 2026.4.10
Timeline
- 2026-04-17: disclosed
- 2026-04-17: patched: Fixed in version 2026.4.10