Incomplete Navigation Guard Vulnerability in OpenClaw by OpenClaw
CVE-2026-43580

4.9MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
6 May 2026

What is CVE-2026-43580?

OpenClaw, prior to version 2026.4.10, contains an incomplete navigation guard vulnerability that poses a risk of unauthorized navigation. Attackers can exploit this flaw by bypassing the server-side request forgery (SSRF) policy enforcement through browser interactions, such as pressing keys or submitting types. This issue may allow malicious actors to initiate navigation without undergoing the necessary security checks, potentially leading to unauthorized access or information disclosure.

Affected Version(s)

OpenClaw 0 < 2026.4.10

OpenClaw 2026.4.10

References

CVSS V4

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zsx (@zsxsoft)
KeenSecurityLab
qclawer
.