← Späť na vyhľadávanie CVE

CVE-2026-41372

OpenClaw

Popis

OpenClaw before 2026.4.2 fails to normalize trailing-dot localhost hosts in remote CDP discovery responses, allowing bypass of loopback protections. Attackers can craft hostile discovery responses returning localhost. to retarget authenticated browser control toward localhost endpoints and expose browser state.

CVSS 5.8EPSS 0.251%Riziko 0.59
Zobraziť zdroj
Zverejnené
2026-04-28 00:16:26
Dotknuté verzie
<2026.4.2
Typ
Core software
Posledná úprava
2026-07-24 21:10:00
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N