Junglewise Threat Intelligence

OpenClaw incomplete navigation guard bypass in browser interactions

Severity: low · CVSS 3.1 · Published 2026-05-06

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a browser automation framework used for testing and interaction workflows. A vulnerability in the navigation guard allows attackers to bypass SSRF (Server-Side Request Forgery) security checks by triggering unauthorized navigation through keyboard and text input interactions, potentially exposing internal resources or causing unintended actions.

Technical details

The vulnerability is an authorization bypass (CWE-862) in OpenClaw's navigation guard mechanism. Browser press/type style interactions (pressKey and type submit flows) can bypass post-action SSRF policy enforcement, allowing navigation without complete security validation. The vulnerability affects all versions before 2026.4.10 and requires network access but no special privileges to exploit. Attackers can trigger unprotected navigation that bypasses intended security policies. A fix was released in version 2026.4.10 through commits addressing the three-phase interaction navigation guard.

Affected products

  • OpenClaw OpenClaw before 2026.4.10

Timeline

  • 2026-04-16: disclosed
  • 2026-04-16: patched: Fixed in version 2026.4.10

References

Related threats