Cross-site request forgery in OpenClaw - CVE-2026-26317
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to trigger unauthorized state changes.
The vulnerability exists due to cross-site request forgery in loopback browser mutation endpoints when handling cross-origin browser requests. A remote attacker can host a malicious website that sends crafted requests to trigger unauthorized state changes.
Exploitation is possible when the browser control service is reachable on loopback in the victim's browser context.