CVE-2026-45000
MEDIUMOpenClaw < 2026.4.20 - Server-Side Request Forgery via Browser CDP Profile Creation
Title source: cnaDescription
OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing to private-network or metadata endpoints that bypass security policies and are later probed during normal profile status operations.
References (4)
Core 4
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-j4c5-89f5-f3pm)
https://github.com/openclaw/openclaw/security/advisories/GHSA-j4c5-89f5-f3pm
Patch patch
Patch Commit (1)
https://github.com/openclaw/openclaw/commit/1fd049e3074cac72f6734a7fe88468c84f5f8bd7
Patch patch
Patch Commit (2)
https://github.com/openclaw/openclaw/commit/e90c89cf8b1459f2aa1f3a665be67392b6c03fdf
Third Party Advisory third-party-advisory
VulnCheck Advisory: OpenClaw < 2026.4.20 - Server-Side Request Forgery via Browser CDP Profile Creation
https://www.vulncheck.com/advisories/openclaw-server-side-request-forgery-via-browser-cdp-profile-creation
Scores
CVSS v3
5.0
EPSS
0.0003
EPSS Percentile
8.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-918
Status
published
Products (3)
OpenClaw/OpenClaw
< 2026.4.20
openclaw/openclaw
< 2026.4.20
OpenClaw/OpenClaw
2026.4.20
Published
May 11, 2026
Tracked Since
May 11, 2026