Loading market data...
← Back to CVE feed

CVE-2026-41372

MEDIUM CVSS 5.8 View on NVD ↗

Description

OpenClaw before 2026.4.2 fails to normalize trailing-dot localhost hosts in remote CDP discovery responses, allowing bypass of loopback protections. Attackers can craft hostile discovery responses returning localhost. to retarget authenticated browser control toward localhost endpoints and expose browser state.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Affected Products

openclaw/openclaw
Published: Apr 28, 2026 00:16 UTC Modified: Apr 28, 2026 18:43 UTC