Missing Authorization in OpenClaw - #VU132738
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in browser debug/export routes when reusing references to already-open browser tabs. A remote user can reference an already-open blocked private-network tab to disclose sensitive information.
Exploitation requires the affected feature to be enabled and reachable, and user interaction is required.