PT-2026-35560 · Openclaw · Openclaw

Keensecuritylab

+1

·

Published

2026-04-27

·

Updated

2026-04-28

·

CVE-2026-41372

CVSS v3.1

5.8

Medium

AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
OpenClaw before 2026.4.2 fails to normalize trailing-dot localhost hosts in remote CDP discovery responses, allowing bypass of loopback protections. Attackers can craft hostile discovery responses returning localhost. to retarget authenticated browser control toward localhost endpoints and expose browser state.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-41372

Affected Products

Openclaw