PT-2026-44897 · Openclaw · Openclaw

Dikai Zou

·

Published

2026-05-29

·

Updated

2026-05-29

·

CVE-2026-35673

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.4.29
Description A Server-Side Request Forgery (SSRF) policy bypass exists in the browser debug and export routes. This issue allows the reuse of already-open blocked tabs, enabling attackers with access to these routes to bypass private-network SSRF policies. Consequently, they can export or inspect content that is intended to remain protected.
Recommendations Update to version 2026.4.29.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-35673

Affected Products

Openclaw