Executive brief
OpenClaw, a tool used for browser automation and management, contains a security flaw in how it handles remote debugging connections. An attacker with low-level access can trick the system into connecting to unauthorized internal servers or external websites. This could allow an attacker to bypass network security controls to access sensitive internal data or pivot their attack to other systems within a corporate network.
Technical details
A server-side request forgery (SSRF) vulnerability exists in OpenClaw versions prior to 2026.4.5 within the CDP /json/version WebSocket endpoint. The root cause is insufficient validation of the 'webSocketDebuggerUrl' field in the response, which allows the application to be redirected to arbitrary hosts. An authenticated attacker can exploit this to perform a 'second-hop' pivot, reaching internal or external targets that should be restricted. The vulnerability is addressed in version 2026.4.5 by normalizing and re-validating direct CDP WebSocket targets before establishing a connection.
Affected products
- OpenClaw openclaw < 2026.4.5
Timeline
- 2026-04-16: advisory: Original GHSA-f7fh-qg34-x2xh published
- 2026-05-06: disclosed: NVD/CVE-2026-43576 published
- 2026-05-11: other: Duplicate advisory GHSA-3r56-7hhr-vfg9 withdrawn