CVE-2026-28458

OpenClaw version 2026.1.20 prior to 2026.2.1 contains a vulnerability in the Browser Relay (extension must be installed and enabled) /cdp WebSocket endpoint in which it does not require authentication tokens, allowing websites to connect via loopback and access sensitive data. Attackers can exploit this by connecting to ws://127.0.0.1:18792/cdp to steal session cookies and execute JavaScript in other browser tabs.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

09 Mar 2026, 17:28

Type Values Removed Values Added
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
First Time Openclaw openclaw
Openclaw
References () https://github.com/openclaw/openclaw/commit/a1e89afcc19efd641c02b24d66d689f181ae2b5c - () https://github.com/openclaw/openclaw/commit/a1e89afcc19efd641c02b24d66d689f181ae2b5c - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-mr32-vwc2-5j6h - () https://github.com/openclaw/openclaw/security/advisories/GHSA-mr32-vwc2-5j6h - Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-missing-authentication-in-browser-relay-cdp-websocket-endpoint - () https://www.vulncheck.com/advisories/openclaw-missing-authentication-in-browser-relay-cdp-websocket-endpoint - Third Party Advisory

09 Mar 2026, 13:36

Type Values Removed Values Added
Summary
  • (es) La versión 2026.1.20 de OpenClaw anterior a la 2026.2.1 contiene una vulnerabilidad en el endpoint WebSocket /cdp del Browser Relay (la extensión debe estar instalada y habilitada) en el que no requiere tokens de autenticación, permitiendo que los sitios web se conecten a través de loopback y accedan a datos sensibles. Los atacantes pueden explotar esto conectándose a ws://127.0.0.1:18792/cdp para robar cookies de sesión y ejecutar JavaScript en otras pestañas del navegador.

06 Mar 2026, 17:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 8.1

05 Mar 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-05 22:16

Updated : 2026-03-09 17:28


NVD link : CVE-2026-28458

Mitre link : CVE-2026-28458

CVE.ORG link : CVE-2026-28458


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-306

Missing Authentication for Critical Function