Incomplete Navigation Guard Vulnerability in OpenClaw by OpenClaw
CVE-2026-43580
4.9MEDIUM
What is CVE-2026-43580?
OpenClaw, prior to version 2026.4.10, contains an incomplete navigation guard vulnerability that poses a risk of unauthorized navigation. Attackers can exploit this flaw by bypassing the server-side request forgery (SSRF) policy enforcement through browser interactions, such as pressing keys or submitting types. This issue may allow malicious actors to initiate navigation without undergoing the necessary security checks, potentially leading to unauthorized access or information disclosure.
Affected Version(s)
OpenClaw 0 < 2026.4.10
OpenClaw 2026.4.10
