Impact
The flaw resides in the clickViaPlaywright function of the Browser Control HTTP API in mf‑yang openclaw‑cn up to version 0.2.1. A crafted HTTP request can cause the server to perform arbitrary outbound requests on its behalf. The vulnerability is a classic server‑side request forgery (CWE‑918) that can be exercised remotely, allowing an attacker to make the server reach internal services, external websites, or other resources without proper validation.
Affected Systems
mf‑yang openclaw‑cn products utilizing the Browser Control HTTP API, specifically releases up to and including 0.2.1. No other vendors or products are presently listed as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate impact, while the EPSS score being below 1% suggests a low likelihood of widespread exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote, triggered by maliciously crafted requests to the clickViaPlaywright endpoint. Successful exploitation could force the server to reach internal networks, exfiltrate data, or further propagate attacks. Due to the lack of a public patch, attackers may still perform the exploit by manipulating the API endpoint.
OpenCVE Enrichment