Description
OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket URLs. Attackers with lower-trust access can reach network destinations that should have been blocked by OpenClaw policy when the affected feature is enabled.
Published: 2026-07-13
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OpenClaw versions before 2026.6.6 allow a policy bypass through its browser CDP discovery mechanism. The flaw permits the use of WebSocket URLs that should have been blocked by OpenClaw’s policy, letting an attacker with lower‑trust access reach internal network destinations that are normally protected. This represents a direct violation of the intended access control model and can lead to confidential data exposure or lateral movement within the protected environment. The weakness is classified as CWE‑918.

Affected Systems

OpenClaw OpenClaw (Node.js) versions before 2026.6.6 are affected. The vulnerability applies to all installations that have the CDP discovery feature enabled.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate risk. EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation yet. The attack vector is inferred to be client‑side, requiring the victim to interact with the affected browser through CDP discovery. An attacker with lower‑trust privileges can craft or inject a WebSocket URL that bypasses the policy, enabling unauthorized access to restricted network resources.

Generated by OpenCVE AI on July 31, 2026 at 11:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenClaw to version 2026.6.6 or newer to remove the policy bypass flaw.
  • If the CDP discovery feature is not required, disable it within the OpenClaw configuration to eliminate the attack surface.
  • Verify that WebSocket URL filtering is correctly enforced by testing reachable URLs and ensuring blocked URLs cannot escape the policy.

Generated by OpenCVE AI on July 31, 2026 at 11:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket URLs. Attackers with lower-trust access can reach network destinations that should have been blocked by OpenClaw policy when the affected feature is enabled.
Title OpenClaw < 2026.6.6 Policy Bypass via CDP Discovery
First Time appeared Openclaw
Openclaw openclaw
Weaknesses CWE-918
CPEs cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Vendors & Products Openclaw
Openclaw openclaw
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N'}


Subscriptions

Openclaw Openclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-14T12:58:20.059Z

Reserved: 2026-07-13T16:38:58.353Z

Link: CVE-2026-62197

cve-icon Vulnrichment

Updated: 2026-07-14T12:58:16.298Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:15:05Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)