Impact
The vulnerability is an improper network binding that allows the Chrome DevTools Protocol to be exposed on all network interfaces. Attackers can use this exposed interface outside the intended sandbox, potentially enabling arbitrary code execution or other malicious actions.
Affected Systems
OpenClaw versions prior to 2026.4.10 are affected. The issue exists in the CDP relay component used by the sandbox browser, which is part of the OpenClaw product suite.
Risk and Exploitability
CVSS score 9.0 marks it as high severity. The EPSS score is not available, so the exploitation probability is currently unknown. It is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability over the network by connecting to the port where the CDP is bound to 0.0.0.0, a configuration that exposes the service to any host.
OpenCVE Enrichment