Server-Side Request Forgery Vulnerability in mf-yang's Openclaw-CN Browser Control API
CVE-2026-17458
Key Information:
- Vendor
Mf-yang
- Status
- Vendor
- CVE Published:
- 26 July 2026
Badges
What is CVE-2026-17458?
A vulnerability exists in the mf-yang Openclaw-CN application, specifically within the Browser Control HTTP API. The flaw, located in the clickViaPlaywright function of the agent.act.ts file, allows attackers to carry out server-side request forgery (SSRF) attacks. This means that by manipulating the application, an attacker can send unauthorized requests from the server, potentially leading to further exploitation. Security advisories indicate that this vulnerability can be exploited remotely and that an initial report was made to the developers, who have yet to address the issue.
Affected Version(s)
openclaw-cn 0.2.0
openclaw-cn 0.2.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
