Junglewise Threat Intelligence

OpenClaw unauthorized file read via CDP navigation pivot

Severity: medium · CVSS 5.9 · Published 2026-04-17

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an AI assistant and automation tool that interacts with web browsers. A security flaw allows the browser to be manipulated into accessing local files or internal debugging interfaces that should be restricted. This could lead to the unauthorized reading of sensitive local files or data from the host system.

Technical details

A vulnerability in OpenClaw's browser interaction handling allows 'act' or 'evaluate' operations to trigger navigations into the local Chrome DevTools Protocol (CDP) origin. By pivoting through this origin, an attacker can bypass existing navigation guards to create or read 'file://' pages. The root cause is a failure to validate URLs after interaction-driven navigations. The fix implements a post-interaction URL check to ensure targets adhere to the configured navigation policy. Exploitation requires user interaction and has high confidentiality impact but no integrity or availability impact.

Affected products

  • openclaw openclaw < 2026.4.9

Timeline

  • 2026-04-16: disclosed
  • 2026-04-17: advisory
  • 2026-04-17: patched: Fixed in version 2026.4.9

References

Related threats