CVE-2026-53812
### Summary OpenClaw's browser control SSRF checks blocked direct navigation to private or loopback URLs, but some Playwright `act` interactions could trigger navigation after the initial check. A later browser evaluation could then read from the page reached by that action-triggered navigation. This issue is specific to browser control actions and private-network navigation policy. Browser evaluation remains an intentional trusted-operator feature when it is used on pages that policy allowed the browser to visit. ### Affected configurations This affects deployments where browser control is enabled and an authenticated browser-control caller can interact with an attacker-controlled page that redirects or navigates the tab to a private-network target through a UI action. ### Impact If the browser reached a private page through an unchecked action-triggered navigation, a caller with browser evaluation capability could read page content that direct navigation policy would have blocked. The issue does not grant access to OpenClaw without authentication. It bypasses the private-network navigation guard for a specific browser action path. ### Patched Versions The first stable patched version is `2026.5.18`. ### Mitigations Upgrade to `[email protected]` or later. Before upgrading, restrict browser-control access to trusted operators and avoid using browser control on untrusted pages in environments with sensitive private web services.
Properties
- severity
- medium
- summary
- OpenClaw's browser act interactions could bypass private-network navigation checks
- epss_score
- 0.00247
- cvss_score
- 7.7
- ghsa_published
- 2026-07-02T16:00:03Z
- source_url
- https://github.com/advisories/GHSA-2hfg-4fh4-qp7f
- ghsa_updated
- 2026-07-02T16:00:03Z
- ghsa_id
- GHSA-2hfg-4fh4-qp7f
- cve_id
- CVE-2026-53812
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
- is_ghsa_only
- false
- epss_percentile
- 0.16255
Related Entities (6)
ENRICHED_BY (1)
AFFECTS (1)
HAS_WEAKNESS (2)
REPORTED_BY (1)
VULNERABLE_TO (1)
Explore deeper with Ninja Signal's threat intelligence graph