PT-2026-99212 · Openclaw · Openclaw
CVE-2026-100576
·
Published
2026-09-26
·
Updated
2026-09-26
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.8.1
Description
An issue exists in browser wait predicates that allows attackers to bypass server-side request forgery (SSRF) protections. By using the
wait --fn function against an existing browser session, an attacker can request loopback or private destinations, as navigation checks applied to other browser actions are not enforced in this context.Recommendations
Update to version 2026.8.1.
As a temporary mitigation, restrict the use of the
wait --fn function.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw