CVE-2026-43573

7.7

OpenClaw · OpenClaw

OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in existing-session browser interaction routes.

Executive summary

An authenticated server-side request forgery policy bypass vulnerability in OpenClaw allows attackers to interact with unauthorized targets due to missing authorization checks.

Vulnerability

This flaw involves missing authorization and server-side request forgery in browser interaction routes, allowing low-privileged authenticated attackers to bypass navigation guards without user interaction.

Business impact

The CVSS score of 7.7 reflects a high severity risk centered around potential system compromise or unauthorized internal resource access. Successful exploitation can permit attackers to bypass security boundaries, leading to unauthorized network interactions and potential exposure of sensitive internal infrastructure.

Remediation

Immediate Action: Update the OpenClaw package to version 2026.4.10 or later using the npm ecosystem update mechanism.

Proactive Monitoring: Monitor network traffic originating from the affected application for unusual outbound requests targeting internal services.

Compensating Controls: Implement strict egress filtering rules at the network perimeter to restrict outbound connections from the hosting environment.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high severity rating, administrators must prioritize updating OpenClaw to version 2026.4.10 immediately. Applying this patch removes the policy bypass flaw and secures browser interaction routes against unauthorized navigational requests.

More OpenClaw CVEs

Sources

Originally found and disclosed by zsx (@zsxsoft), with KeenSecurityLab (coordinator), qclawer (tool), per the CVE Program record.