Impact
OpenClaw versions released before 2026.5.18 have a server‑side request forgery issue in the browser control module. The flaw lets an authenticated user trigger Playwright action‑based redirects that bypass private‑network navigation restrictions. Once the navigation occurs, the attacker can use browser evaluation features to read page content that is normally only accessible within the private network, thereby exposing confidential data. This weakness is captured by CWE‑918.
Affected Systems
The vulnerability affects all OpenClaw installations running a version older than 2026.5.18 where Playwright browser control is enabled. Any user with valid authentication credentials can exploit the flaw to target internal resources.
Risk and Exploitability
The CVSS score of 4.9 indicates that the vulnerability is of moderate severity. Exploitation requires the attacker to be authenticated and to have access to the Playwright interface, which limits the attack surface to trusted or compromised user accounts. The EPSS score is unavailable and the issue is not listed in CISA KEV, suggesting a lower public exploitation probability at present. Nonetheless, compromised credentials could allow internal data leakage through the private‑network navigation bypass.
OpenCVE Enrichment