CVE-2026-35643

HIGH

OpenClaw < 2026.3.22 - Arbitrary Code Execution via Unvalidated WebView JavascriptInterface

Title source: cna
STIX 2.1

Description

OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing attackers to inject arbitrary instructions. Untrusted pages can invoke the canvas bridge to execute malicious code within the Android application context.

References (4)

Core 4
Core References
Third Party Advisory third-party-advisory
GitHub Security Advisory (GHSA-cxmw-p77q-wchg)
https://github.com/openclaw/openclaw/security/advisories/GHSA-cxmw-p77q-wchg
Third Party Advisory third-party-advisory
VulnCheck Advisory: OpenClaw < 2026.3.22 - Arbitrary Code Execution via Unvalidated WebView JavascriptInterface
https://www.vulncheck.com/advisories/openclaw-arbitrary-code-execution-via-unvalidated-webview-javascriptinterface

Scores

CVSS v3 8.8
EPSS 0.0037
EPSS Percentile 28.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-940
Status published
Products (4)
npm/openclaw 0 - 2026.3.22npm
OpenClaw/OpenClaw < 2026.3.22
openclaw/openclaw < 2026.3.22
OpenClaw/OpenClaw 2026.3.22
Published Apr 10, 2026
Tracked Since Apr 10, 2026