CVE-2026-32008

OpenClaw versions prior to 2026.2.21 contain an improper URL scheme validation vulnerability in the assertBrowserNavigationAllowed() function that allows authenticated users with browser-tool access to navigate to file:// URLs. Attackers can exploit this by accessing local files readable by the OpenClaw process user through browser snapshot and extraction actions to exfiltrate sensitive data.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

23 Mar 2026, 17:34

Type Values Removed Values Added
Summary
  • (es) Las versiones de OpenClaw anteriores a la 2026.2.21 contienen una vulnerabilidad de validación de esquema de URL incorrecta en la función assertBrowserNavigationAllowed() que permite a los usuarios autenticados con acceso a la herramienta del navegador navegar a URLs de tipo file://. Los atacantes pueden explotar esto accediendo a archivos locales legibles por el usuario del proceso de OpenClaw a través de acciones de captura y extracción del navegador para exfiltrar datos sensibles.
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
First Time Openclaw openclaw
Openclaw
References () https://github.com/openclaw/openclaw/commit/220bd95eff6838234e8b4b711f86d4565e16e401 - () https://github.com/openclaw/openclaw/commit/220bd95eff6838234e8b4b711f86d4565e16e401 - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-45cg-2683-gfmq - () https://github.com/openclaw/openclaw/security/advisories/GHSA-45cg-2683-gfmq - Exploit, Mitigation, Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-arbitrary-local-file-read-via-browser-navigation-guard - () https://www.vulncheck.com/advisories/openclaw-arbitrary-local-file-read-via-browser-navigation-guard - Third Party Advisory

20 Mar 2026, 18:16

Type Values Removed Values Added
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-45cg-2683-gfmq - () https://github.com/openclaw/openclaw/security/advisories/GHSA-45cg-2683-gfmq -

19 Mar 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-19 22:16

Updated : 2026-03-23 17:34


NVD link : CVE-2026-32008

Mitre link : CVE-2026-32008

CVE.ORG link : CVE-2026-32008


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-610

Externally Controlled Reference to a Resource in Another Sphere