PT-2026-34778 · Openclaw · Openclaw

Antaisecuritylab

·

Published

2026-04-03

·

Updated

2026-04-25

·

CVE-2026-41347

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.31
Description When operating in trusted-proxy mode, the software lacks browser-origin validation in HTTP operator endpoints. This allows cross-site request forgery (CSRF) attacks, where attackers send malicious requests from a browser in trusted-proxy deployments to perform unauthorized actions on HTTP operator endpoints.
Recommendations Update to version 2026.3.31.

Fix

CSRF

Origin Validation Error

Weakness Enumeration

Related Identifiers

CVE-2026-41347
GHSA-2XP4-QHR4-XQM2
GHSA-MHR7-2XMV-4C4Q

Affected Products

Openclaw