CVE-2026-35643

OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing attackers to inject arbitrary instructions. Untrusted pages can invoke the canvas bridge to execute malicious code within the Android application context.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

13 Apr 2026, 19:59

Type Values Removed Values Added
References () https://github.com/openclaw/openclaw/commit/630f1479c44f78484dfa21bb407cbe6f171dac87 - () https://github.com/openclaw/openclaw/commit/630f1479c44f78484dfa21bb407cbe6f171dac87 - Patch
References () https://github.com/openclaw/openclaw/commit/8b02ef133275be96d8aac2283100016c8a7f32e5 - () https://github.com/openclaw/openclaw/commit/8b02ef133275be96d8aac2283100016c8a7f32e5 - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-cxmw-p77q-wchg - () https://github.com/openclaw/openclaw/security/advisories/GHSA-cxmw-p77q-wchg - Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-arbitrary-code-execution-via-unvalidated-webview-javascriptinterface - () https://www.vulncheck.com/advisories/openclaw-arbitrary-code-execution-via-unvalidated-webview-javascriptinterface - Third Party Advisory
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
First Time Openclaw openclaw
Openclaw

10 Apr 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-10 17:17

Updated : 2026-06-17 10:40


NVD link : CVE-2026-35643

Mitre link : CVE-2026-35643

CVE.ORG link : CVE-2026-35643


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-940

Improper Verification of Source of a Communication Channel