PT-2026-25132 · Npm · Openclaw

Publicado

2026-03-02

·

Atualizado

2026-03-02

CVSS v4.0

7.5

Alta

VetorAV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

Summary

When browser control started without explicit auth credentials, OpenClaw attempted to bootstrap auth automatically. In affected versions, if that bootstrap step threw an error, startup could continue and expose browser-control routes without authentication.

Impact

On affected deployments, a local process (or a loopback-reachable SSRF path) could access browser-control routes, including evaluate-capable actions, without auth.

Fix

Startup now fails closed: if bootstrap auth fails and no explicit token/password is configured, browser-control startup aborts.

Affected and Patched Versions

  • Affected: <= 2026.2.26
  • Patched: 2026.3.1

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-VPJ2-69HF-RPPW

Produtos afetados

Openclaw