Junglewise Threat Intelligence

OpenClaw missing authentication in sandbox noVNC helper route

Severity: medium · CVSS 6.9 · Published 2026-04-17

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an AI assistant platform. A security flaw in its sandbox component allowed unauthorized access to interactive browser sessions. This could lead to the exposure of session credentials and allow an attacker to view or interact with a user's browser session without proper authentication.

Technical details

A vulnerability exists in OpenClaw where the sandbox noVNC helper route was accessible without the required bridge authentication (CWE-306). This allowed unauthenticated network attackers to reach the interactive browser session surface and potentially obtain session credentials. The root cause was a failure to gate the specific helper route behind the application's authentication bridge. The issue has been resolved in version 2026.4.10 by enforcing bridge authentication for the affected route.

Affected products

  • openclaw openclaw >= 2026.2.21 < 2026.4.10

Timeline

  • 2026-04-16: patched: First stable tag v2026.4.10 released
  • 2026-04-17: advisory

References

Related threats