GHSA-2pcx-9jr9-59mgHighCVSS 8.3

OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that...

Published
September 26, 2026
Last Modified
September 26, 2026

🔗 CVE IDs covered (1)

📋 Description

OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions to access paired node browser actions despite allowHostControl=false configuration. Attackers with control over sandboxed agent input can select a paired node and perform host browser operations, inspecting or manipulating the connected browser profile and its authenticated state.

🔗 References (4)