Openclaw · Openclaw · CVE-2026-62197
**Name of the Vulnerable Software and Affected Versions**
OpenClaw versions prior to 2026.6.6
**Description**
A policy bypass exists in the browser CDP (Chrome DevTools Protocol) discovery feature. This issue allows the system to accept blocked WebSocket URLs, enabling attackers with lower-trust access to reach network destinations that should have been restricted by the OpenClaw policy when the feature is active.
**Recommendations**
Update to version 2026.6.6 or later.
As a temporary mitigation, disable the browser CDP discovery feature.