Improper access control in OpenClaw - CVE-2026-42430
Published: April 30, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to reach private network targets.
The vulnerability exists due to improper access control in Playwright redirect handling when processing request-time navigation redirects. A remote user can trigger a redirect to a private target to reach private network targets.
The issue is scoped to the product's local assistant trust model.