Protection Mechanism Failure in OpenClaw - #VU128591
Published: April 30, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to read disallowed local files.
The vulnerability exists due to protection mechanism failure in browser interaction routes when triggering interaction-driven navigations into the local CDP origin. A remote user can cause navigation to the local CDP origin and then create or read disallowed file:// pages to read disallowed local files.
The issue occurs despite direct navigation guards.