OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that exposes Chrome DevTools Protocol on 0.0.0.0. Attackers can access the DevTools protocol outside intended local sandbox boundaries by exploiting the overly broad binding configuration.
The vulnerability stems from an overly broad CDP (Chrome DevTools Protocol) relay binding configuration in the sandboxed browser — instead of listening only on the local interface (localhost/127.0.0.1), the service exposes CDP on all network interfaces (0.0.0.0). An attacker with access to the same network (attack vector AV:A) can connect to the DevTools protocol without authentication and perform operations beyond sandbox isolation boundaries.
An attacker can gain full access to browser sessions via Chrome DevTools Protocol, enabling reading and modifying sensitive data, executing JavaScript code in the browser context, and potentially breaking sandbox isolation. High impact on confidentiality, integrity, and availability affects both local components and external systems (C:H/I:H/A:H).
OpenClaw should be updated to version 2026.4.10 or later, which fixes the CDP relay binding configuration (commit fbf11ebdb7110632f93926d0ac7b48f04cb44d77). Until the update is deployed, it is recommended to restrict network access to CDP ports using firewall rules and isolate hosts running OpenClaw from untrusted network segments.
OpenClaw versions before 2026.4.10
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XOpenclaw
APPOpenclaw< 2026.4.10
Related vulnerabilities
OpenClaw — Auth Bypass w walidacji Feishu webhook umożliwia RCE
OpenClaw: Authentication Bypass w trasie pomocniczej sandbox noVNC
OpenClaw: privilege escalation przez pominięcie zdarzeń async exec w heartbeat
OpenClaw: ominięcie uwierzytelniania przez nieodświeżane tokeny bearer po rotacji SecretRef
OpenClaw: nieweryfikowane metadane hooków eskalowane do kontekstu systemowego