Junglewise Threat Intelligence

OpenClaw SSRF via DNS rebinding in browser navigation policy

Severity: medium · CVSS 6.3 · Published 2026-05-06

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a tool used for browser-based automation and navigation. A security flaw in its navigation policy allows attackers to bypass safety checks that are supposed to prevent the software from accessing internal or private network resources. By exploiting this, an attacker could gain unauthorized access to sensitive internal data or services that are not intended to be exposed to the internet.

Technical details

OpenClaw before version 2026.4.10 is vulnerable to a Server-Side Request Forgery (SSRF) bypass due to a Time-of-Check Time-of-Use (TOCTOU) flaw in its hostname validation logic. The browser navigation policy validates a hostname's IP resolution at one point in time, but the underlying Chromium instance may resolve the same hostname to a different (internal) IP address during the actual network request. This DNS rebinding attack allows an authenticated attacker with low privileges to pivot from the browser interface to unallowlisted internal resources. The fix, introduced in version 2026.4.10, tightens hostname navigation by failing closed unless the hostname is an explicit allowlist exception or an IP literal.

Affected products

  • openclaw openclaw < 2026.4.10

Timeline

  • 2026-04-10: patched: Fix committed in version 2026.4.10
  • 2026-05-06: disclosed: Initial advisory published
  • 2026-05-11: advisory: Advisory withdrawn as duplicate of GHSA-xq94-r468-qwgj

References

Related threats