PT-2026-35560 · Openclaw · Openclaw
Keensecuritylab
+1
·
Published
2026-04-07
·
Updated
2026-04-28
·
CVE-2026-41372
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.4.2
Description
The software fails to normalize trailing-dot localhost hosts in remote CDP (Chrome DevTools Protocol) discovery responses. This allows the bypass of loopback protections, enabling attackers to craft hostile discovery responses returning
localhost. to retarget authenticated browser control toward localhost endpoints and expose browser state.Recommendations
Update to version 2026.4.2.
Fix
IDOR
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw