Loading market data...
← Back to CVE feed

CVE-2026-41912

HIGH CVSS 7.6 View on NVD ↗

Description

OpenClaw before 2026.4.8 contains a server-side request forgery policy bypass vulnerability allowing attackers to trigger navigations bypassing normal SSRF checks. Attackers can exploit browser interactions to bypass SSRF protections and access restricted resources.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Published: Apr 28, 2026 19:37 UTC Modified: Apr 28, 2026 20:10 UTC