Improper access control in OpenClaw - #VU129398
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a local user to interfere with extension-relay behavior.
The vulnerability exists due to improper access control in the /extension endpoint when handling WebSocket upgrade requests. A local user can connect to the endpoint without the token to interfere with extension-relay behavior.
Only instances with the optional Chrome extension relay enabled are vulnerable.