PT-2026-64808 · Mf Yang · Openclaw-Cn
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
mf-yang openclaw-cn versions prior to 0.2.2
Description
A remote information disclosure issue exists in the Scheme Handler component. The problem resides in the
assertBrowserNavigationAllowed() function within the src/browser/navigation-guard.ts file. An attacker can exploit this by manipulating the url argument to disclose sensitive information.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary mitigation, restrict the use of the
assertBrowserNavigationAllowed() function.Exploit
Information Disclosure
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw-Cn