Externally Controlled Reference to a Resource in Another Sphere in OpenClaw - CVE-2026-32008
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to externally controlled reference to a resource in another sphere in assertBrowserNavigationAllowed() in src/browser/navigation-guard.ts when handling browser navigation to non-network URL schemes. A remote user can navigate a browser session to a crafted file:// URL to disclose sensitive information.
Only instances with browser tooling enabled are vulnerable, and exploitation requires the ability to invoke browser actions.