Origin validation error in OpenClaw - CVE-2026-41347
Published: April 30, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to perform cross-site request forgery against operator endpoints.
The vulnerability exists due to improper origin validation in HTTP operator endpoints when operating in trusted-proxy mode. A remote user can cause the victim's browser to send a crafted request to perform cross-site request forgery against operator endpoints.
Exploitation depends on identity-bearing trusted-proxy browser deployments rather than the shared-secret HTTP operator model.