Executive brief
OpenClaw is a platform that provides HTTP operator endpoints for managing and controlling workflow operations. When deployed in trusted-proxy mode, these endpoints fail to validate the origin of browser requests, allowing attackers to exploit cross-site request forgery (CSRF) vulnerabilities. An attacker could trick a logged-in user into performing unauthorized actions on the HTTP operator endpoints, potentially compromising operations or data integrity in trusted-proxy deployments.
Technical details
This vulnerability is a cross-site request forgery (CWE-352) affecting OpenClaw's HTTP operator endpoints in trusted-proxy mode. The root cause is the absence of browser-origin validation on these endpoints when operating behind a trusted proxy. An attacker with network access can craft a malicious web page or email that, when visited by a user with an active session to the vulnerable OpenClaw instance, sends an unauthorized HTTP request to the operator endpoints. The vulnerability requires user interaction (a user must visit a malicious site while authenticated) and is specific to browser-based trusted-proxy deployments, not headless proxy clients using shared secrets. The fix, released in version 2026.3.31, implements Origin header validation on trusted-proxy HTTP operator requests while maintaining compatibility with origin-less headless proxy clients.
Affected products
- OpenClaw openclaw <=2026.3.28
Timeline
- 2026-03-31: disclosed
- 2026-03-31: patched: Fix released in version 2026.3.31