PT-2026-25132 · Npm · Openclaw
Published
2026-03-02
·
Updated
2026-03-02
CVSS v4.0
7.5
High
| Vector | AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Summary
When browser control started without explicit auth credentials, OpenClaw attempted to bootstrap auth automatically. In affected versions, if that bootstrap step threw an error, startup could continue and expose browser-control routes without authentication.
Impact
On affected deployments, a local process (or a loopback-reachable SSRF path) could access browser-control routes, including evaluate-capable actions, without auth.
Fix
Startup now fails closed: if bootstrap auth fails and no explicit token/password is configured, browser-control startup aborts.
Affected and Patched Versions
- Affected:
<= 2026.2.26 - Patched:
2026.3.1
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw