Input validation error in OpenClaw - CVE-2026-41372
Published: April 30, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper input validation in remote CDP discovery host normalization when processing discovery responses. A remote user can return a crafted discovery response with a trailing-dot localhost host to disclose sensitive information.
Exploitation can retarget authenticated browser control to a localhost-resolving endpoint on the OpenClaw host.