Server-Side Request Forgery Vulnerability in OpenClaw by OpenClaw Inc.
CVE-2026-62227
4.9MEDIUM
What is CVE-2026-62227?
The OpenClaw software version 2026.4.14 prior to 2026.5.26 contains a security flaw that allows for server-side request forgery through its browser snapshot routes. This vulnerability arises from inadequate validation of post-navigation destinations. Consequently, attackers with lower-trust access levels can exploit this weakness to bypass OpenClaw's intended policy checks. As a result, unauthorized network destinations can be accessed, potentially leading to sensitive data exposure or disruption of services.
Affected Version(s)
OpenClaw 2026.4.14 < 2026.5.26
OpenClaw 2026.5.26
