CVE-2026-43573
7.7OpenClaw · OpenClaw
OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in existing-session browser interaction routes.
Executive summary
An authenticated server-side request forgery policy bypass vulnerability in OpenClaw allows attackers to interact with unauthorized targets due to missing authorization checks.
Vulnerability
This flaw involves missing authorization and server-side request forgery in browser interaction routes, allowing low-privileged authenticated attackers to bypass navigation guards without user interaction.
Business impact
The CVSS score of 7.7 reflects a high severity risk centered around potential system compromise or unauthorized internal resource access. Successful exploitation can permit attackers to bypass security boundaries, leading to unauthorized network interactions and potential exposure of sensitive internal infrastructure.
Remediation
Immediate Action: Update the OpenClaw package to version 2026.4.10 or later using the npm ecosystem update mechanism.
Proactive Monitoring: Monitor network traffic originating from the affected application for unusual outbound requests targeting internal services.
Compensating Controls: Implement strict egress filtering rules at the network perimeter to restrict outbound connections from the hosting environment.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high severity rating, administrators must prioritize updating OpenClaw to version 2026.4.10 immediately. Applying this patch removes the policy bypass flaw and secures browser interaction routes against unauthorized navigational requests.
More OpenClaw CVEs
Sources
Originally found and disclosed by zsx (@zsxsoft), with KeenSecurityLab (coordinator), qclawer (tool), per the CVE Program record.
- GitHub Security Advisory (GHSA-527m-976r-jf79) Vendor advisory
- Patch Commit Patch commit
- VulnCheck Advisory: OpenClaw < 2026.4.10 - SSRF Policy Bypass in Existing-Session Browser Interaction Routes Third-party advisory