Impact
The vulnerability is a server‑side request forgery in OpenClaw’s browser snapshot functionality that allows an attacker to trigger requests to arbitrary internal network destinations without proper validation. Attackers with lower‑trust access can bypass policy checks and reach resources that should otherwise be blocked, exposing the system to unintended data disclosure and potential lateral movement. The flaw is a classic SSRF (CWE‑918) and was found in versions 2026.4.14 through 2026.5.25.
Affected Systems
OpenClaw application versions earlier than 2026.5.26 are affected. The vulnerability exists in the browser snapshot routes of the OpenClaw web service, which runs on a Node.js environment.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack path requires the ability to access the OpenClaw application and invoke the browser snapshot API, typically through an authenticated user with limited permissions. Once triggered, the attacker can send requests to any host reachable from the server, allowing bypass of policy controls and potential internal exposure. The likely attack vector is a web‑based exploitation utilizing the browser snapshot endpoint with crafted URLs.
OpenCVE Enrichment