PT-2026-38236 · Openclaw · Openclaw

·

CVE-2026-43581

·

Published

2026-04-17

·

Updated

2026-05-14

CVSS v3.1

9.6

Critical

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.4.10
Description An improper network binding issue exists in the sandbox browser CDP relay, which exposes the Chrome DevTools Protocol on 0.0.0.0. This overly broad binding configuration allows attackers to access the DevTools protocol from outside the intended local sandbox boundaries.
Recommendations Update to version 2026.4.10.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43581
GHSA-525J-HQQ2-66R4

Affected Products

Openclaw