Junglewise Threat Intelligence

CVE-2026-62201: OpenClaw network policy bypass in sandbox exec-server

CVE-2026-62201 · Severity: high · CVSS 7.7 · Published 2026-07-17

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a platform used for executing code and managing network requests within a sandboxed environment. A security flaw in its execution server allows users with low-level access to bypass network restrictions and reach internal systems that should be blocked. This could lead to the exposure of sensitive internal data or unauthorized access to private network resources.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the OpenClaw sandbox exec-server component. The flaw allows an authenticated, low-privileged attacker to bypass configured network policies by sending HTTP requests through the exec-server to reach restricted internal network destinations. The vulnerability is characterized by a scope change (S:C), meaning the exploit allows access to resources outside the intended security boundary of the sandbox. The issue is addressed in version 2026.6.6; users are advised to upgrade or restrict access to the affected feature to trusted operators.

Affected products

  • OpenClaw OpenClaw < 2026.6.6

Timeline

  • 2026-06-30: advisory: GitHub Security Advisory published
  • 2026-07-17: disclosed: CVE published to NVD
  • 2026-06-30: patched: Version 2026.6.6 released

References

Related threats