PT-2026-39689 · Openclaw · Openclaw

Nicky

·

Published

2026-05-11

·

Updated

2026-05-11

·

CVE-2026-45000

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing to private-network or metadata endpoints that bypass security policies and are later probed during normal profile status operations.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-45000

Affected Products

Openclaw