Improper access control in OpenClaw - #VU132702
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information from private-network pages.
The vulnerability exists due to improper access control in browser control act interactions when handling action-triggered navigation to private or loopback URLs. A remote user can interact with an attacker-controlled page that redirects or navigates the tab to a private-network target through a UI action to disclose sensitive information from private-network pages.
Exploitation requires browser control to be enabled and browser evaluation capability to be available.