Executive brief
OpenClaw, a tool used for managing browser-based snapshots and gateway operations, contains a security flaw in how it handles web requests. An attacker with low-level access can trick the system into connecting to internal network destinations that are normally restricted. This could allow an unauthorized user to view sensitive internal data or probe private infrastructure that should be protected by the software's security policies.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in OpenClaw versions 2026.4.14 through 2026.5.25 within the browser snapshot routes. The root cause is a failure to validate destinations after a browser navigation event has occurred. An authenticated attacker with low privileges can exploit this over the network to bypass configured security policies and reach internal network resources. This vulnerability is assigned CWE-918 and carries a CVSS v3.1 score of 7.7, reflecting a high confidentiality impact due to the potential for internal data exposure. The issue is resolved in version 2026.5.26.
Affected products
- OpenClaw OpenClaw 2026.4.14 to 2026.5.25
Timeline
- 2026-06-30: advisory: GHSA-2x93-h3hg-2xfp published
- 2026-07-16: disclosed: CVE-2026-62227 published to NVD
- 2026-05-26: patched: Version 2026.5.26 released