CVE-2026-32008
MEDIUMOpenClaw < 2026.2.21 - Arbitrary Local File Read via Browser Navigation Guard
Title source: cnaDescription
OpenClaw versions prior to 2026.2.21 contain an improper URL scheme validation vulnerability in the assertBrowserNavigationAllowed() function that allows authenticated users with browser-tool access to navigate to file:// URLs. Attackers can exploit this by accessing local files readable by the OpenClaw process user through browser snapshot and extraction actions to exfiltrate sensitive data.
Scores
CVSS v3
6.5
EPSS
0.0004
EPSS Percentile
12.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-610
Status
published
Products (3)
npm/openclaw
0 - 2026.2.21npm
OpenClaw/OpenClaw
< 2026.2.21
OpenClaw/OpenClaw
2026.2.21
Published
Mar 19, 2026
Tracked Since
Mar 20, 2026