PT-2026-26390 · Openclaw · Openclaw

Q1Uf3Ng

·

Published

2026-03-19

·

Updated

2026-03-19

·

CVE-2026-32008

CVSS v3.1

6.5

Medium

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
OpenClaw versions prior to 2026.2.21 contain an improper URL scheme validation vulnerability in the assertBrowserNavigationAllowed() function that allows authenticated users with browser-tool access to navigate to file:// URLs. Attackers can exploit this by accessing local files readable by the OpenClaw process user through browser snapshot and extraction actions to exfiltrate sensitive data.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-32008

Affected Products

Openclaw