Executive brief
OpenClaw is a browser automation and testing platform. An exposed helper route in the sandbox noVNC (virtual network display) component could be accessed without required authentication, allowing attackers to reach an interactive browser session interface and potentially view or interact with active sessions without authorization.
Technical details
The vulnerability is an authentication bypass (CWE-306) in the sandbox noVNC helper route handler. The route was not properly gated behind bridge authentication middleware, allowing unauthenticated network requests to reach the interactive browser session surface. The fix gates the helper route behind bridge authentication and ensures the authentication middleware is invoked before route registration to prevent future ordering bypass. No user interaction or special preconditions are required—the helper route is network-reachable without authentication. An attacker can gain access to interactive browser session credentials or surfaces. The fix was merged in PR #63882 and released in version 2026.4.10 and later.
Affected products
- OpenClaw openclaw >= 2026.2.21 < 2026.4.10
Timeline
- 2026-04-17: disclosed
- 2026-04-10: patched: Fix merged in PR #63882; version 2026.4.10 and later