Improper access control in OpenClaw - #VU126446
Published: April 17, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to trigger server-side request forgery policy bypass.
The vulnerability exists due to improper access control in browser press/type interaction routes when triggering navigation-capable interactions. A remote attacker can cause pressKey or type submit flows to initiate navigation to trigger server-side request forgery policy bypass.