Impact
OpenClaw versions before 2026.6.6 allow a policy bypass through its browser CDP discovery mechanism. The flaw permits the use of WebSocket URLs that should have been blocked by OpenClaw’s policy, letting an attacker with lower‑trust access reach internal network destinations that are normally protected. This represents a direct violation of the intended access control model and can lead to confidential data exposure or lateral movement within the protected environment. The weakness is classified as CWE‑918.
Affected Systems
OpenClaw OpenClaw (Node.js) versions before 2026.6.6 are affected. The vulnerability applies to all installations that have the CDP discovery feature enabled.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate risk. EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation yet. The attack vector is inferred to be client‑side, requiring the victim to interact with the affected browser through CDP discovery. An attacker with lower‑trust privileges can craft or inject a WebSocket URL that bypasses the policy, enabling unauthorized access to restricted network resources.
OpenCVE Enrichment