CVE-2026-41912

HIGH
7.6CVSS v3
CVSS v2
0.21% EPSS (exploit probability)
CWE-918CWE

Description

OpenClaw before 2026.4.8 contains a server-side request forgery policy bypass vulnerability allowing attackers to trigger navigations bypassing normal SSRF checks. Attackers can exploit browser interactions to bypass SSRF protections and access restricted resources.

CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references