PT-2026-99212 · Openclaw · Openclaw

CVE-2026-100576

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.8.1
Description An issue exists in browser wait predicates that allows attackers to bypass server-side request forgery (SSRF) protections. By using the wait --fn function against an existing browser session, an attacker can request loopback or private destinations, as navigation checks applied to other browser actions are not enforced in this context.
Recommendations Update to version 2026.8.1. As a temporary mitigation, restrict the use of the wait --fn function.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100576
GHSA-4G58-43JR-6738

Affected Products

Openclaw