Executive brief
OpenClaw, a tool used for browser-based automation and gateway operations, contains a flaw where debug and export features can accidentally reuse browser tabs that were previously blocked for security reasons. If exploited, an attacker could bypass network protections to view or export sensitive content from private internal networks. This could lead to the exposure of internal data that the system was specifically configured to protect.
Technical details
A missing authorization or policy re-application flaw (CWE-862) exists in OpenClaw's browser debug and export routes. In affected versions, a caller capable of referencing an existing browser tab can reuse tabs that were previously blocked by private-network or SSRF policies without those policies being reapplied. This allows for the inspection or exportation of content from tabs that should remain restricted under the browser network policy. The attack requires network access, low privileges, and user interaction, and is mitigated by upgrading to version 2026.4.29 or restricting access to debug routes.
Affected products
- openclaw openclaw < 2026.4.29
Timeline
- 2026-05-28: disclosed: Initial disclosure to maintainers
- 2026-07-02: advisory: GitHub Advisory published
- 2026-04-29: patched: First stable patched version released