Junglewise Threat Intelligence

CVE-2026-62197: OpenClaw policy bypass in browser CDP discovery

CVE-2026-62197 · Severity: high · CVSS 8.5 · Published 2026-07-13

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a tool used for browser automation and discovery, contains a security flaw in how it handles network connections. An attacker with low-level access could bypass security policies to reach internal network destinations that should be restricted. This could lead to unauthorized access to sensitive internal data or services.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in OpenClaw's browser Chrome DevTools Protocol (CDP) discovery feature. The component fails to properly validate WebSocket URLs against established security policies, allowing them to bypass intended blocks. An authenticated attacker with 'lower-trust' access can exploit this to reach internal network destinations. The vulnerability is present when the CDP discovery feature is enabled and reachable by untrusted inputs. A fix is available in version 2026.6.6.

Affected products

  • OpenClaw OpenClaw before 2026.6.6

Timeline

  • 2026-06-30: advisory: GitHub Security Advisory published
  • 2026-07-13: disclosed: NVD publication date

References

Related threats