CVE-2026-22174

MEDIUM

OpenClaw < 2026.2.22 - Gateway Token Disclosure via Chrome CDP Probe

Title source: cna

Description

OpenClaw versions prior to 2026.2.22 inject the x-OpenClaw-relay-token header into Chrome CDP probe traffic on loopback interfaces, allowing local processes to capture the Gateway authentication token. An attacker controlling a loopback port can intercept CDP reachability probes to the /json/version endpoint and reuse the leaked token as Gateway bearer authentication.

Scores

CVSS v3 6.8
EPSS 0.0002
EPSS Percentile 6.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Details

CWE
CWE-306
Status published
Products (3)
npm/openclaw 0 - 2026.2.22npm
OpenClaw/OpenClaw < 2026.2.22
openclaw/openclaw < 2026.2.22
Published Mar 18, 2026
Tracked Since Mar 18, 2026