CVE-2026-53812Medium· 7.7▾ SunlitOpenClaw's browser act interactions could bypass private-network navigation checks
▾ Sunlit zone — Low / medium · no exploitation signal
impact 42.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.2%
OpenClaw's browser control SSRF checks blocked direct navigation to private or loopback URLs, but some Playwright act interactions could trigger navigation after the initial check. A later browser evaluation could then read from the page reached by that action-triggered navigation.
This issue is specific to browser control actions and private-network navigation policy. Browser evaluation remains an intentional trusted-operator feature when it is used on pages that policy allowed the browser to visit.
This affects deployments where browser control is enabled and an authenticated browser-control caller can interact with an attacker-controlled page that redirects or navigates the tab to a private-network target through a UI action.
If the browser reached a private page through an unchecked action-triggered navigation, a caller with browser evaluation capability could read page content that direct navigation policy would have blocked.
The issue does not grant access to OpenClaw without authentication. It bypasses the private-network navigation guard for a specific browser action path.
The first stable patched version is 2026.5.18.
Upgrade to [email protected] or later. Before upgrading, restrict browser-control access to trusted operators and avoid using browser control on untrusted pages in environments with sensitive private web services.
openclaw < 2026.5.18Upgrade to a patched release:
openclaw 2026.5.18Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53816High· 7.2OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance
GHSA-xww8-gqvh-92x9High· 8.0OpenClaw: Exec approval display truncation could hide the command being approved
GHSA-qh2f-99mv-mrcfMediumOpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn
GHSA-2j8v-hwgc-x698HighOpenClaw: Shell wrapper argv could change between approval and execution
CVE-2026-53810High· 8.8OpenClaw's marketplace runtime extension metadata could point at unscanned payloads
GHSA-rggc-m335-3wvjHighOpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers