---
id: CVE-2026-101883
title: >-
  OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery
  vulnerability in the canvas.present capability that bypasses URL risk
  evaluation enforced by canvas.navigate
summary: >-
  OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery
  vulnerability in the canvas.present capability that bypasses URL risk
  evaluation enforced by canvas.navigate. Attackers with gateway or agent access
  can issue …
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-918
vendor: OpenClaw
product: OpenClaw Windows Node
affected:
  - windows_node <= 2026.9.4
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T20:17:20.197'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101883'
references:
  - url: >-
      https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Tray.WinUI/Windows/CanvasWindow.xaml.cs#L77-L109
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/openclaw/openclaw-windows-node/blob/v2026.9.4/src/OpenClaw.Tray.WinUI/Services/NodeService.cs#L1244-L1270
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/openclaw/openclaw-windows-node/commit/16528aadaa45d7bc6718b07ccf8b01f3eb033ad1
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-7vch-pmw9-3g4q
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-windows-node-through-2026.9.4-ssrf-via-canvas-present
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T20:23:19.512Z'
---

## Overview

OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability that bypasses URL risk evaluation enforced by canvas.navigate. Attackers with gateway or agent access can issue canvas.present to make the node's WebView send requests to localhost, private networks, or tailnet services from the user's machine.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
