CVE-2026-22174

OpenClaw versions prior to 2026.2.22 inject the x-OpenClaw-relay-token header into Chrome CDP probe traffic on loopback interfaces, allowing local processes to capture the Gateway authentication token. An attacker controlling a loopback port can intercept CDP reachability probes to the /json/version endpoint and reuse the leaked token as Gateway bearer authentication.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

25 Mar 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.7
v2 : unknown
v3 : 6.8

19 Mar 2026, 14:54

Type Values Removed Values Added
First Time Openclaw openclaw
Openclaw
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
References () https://github.com/openclaw/openclaw/commit/afa22acc4a09fdf32be8a167ae216bee85c30dad - () https://github.com/openclaw/openclaw/commit/afa22acc4a09fdf32be8a167ae216bee85c30dad - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-v3j7-34xh-6g3w - () https://github.com/openclaw/openclaw/security/advisories/GHSA-v3j7-34xh-6g3w - Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-gateway-token-disclosure-via-chrome-cdp-probe - () https://www.vulncheck.com/advisories/openclaw-gateway-token-disclosure-via-chrome-cdp-probe - Third Party Advisory

18 Mar 2026, 14:52

Type Values Removed Values Added
Summary
  • (es) Las versiones de OpenClaw anteriores a 2026.2.22 inyectan el encabezado x-OpenClaw-relay-token en el tráfico de sondeo de Chrome CDP en interfaces de bucle invertido, lo que permite a los procesos locales capturar el token de autenticación de Gateway. Un atacante que controla un puerto de bucle invertido puede interceptar sondeos de accesibilidad CDP al endpoint /json/version y reutilizar el token filtrado como autenticación de portador de Gateway.

18 Mar 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-18 02:16

Updated : 2026-03-25 15:16


NVD link : CVE-2026-22174

Mitre link : CVE-2026-22174

CVE.ORG link : CVE-2026-22174


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-306

Missing Authentication for Critical Function