CVE-2026-41912
HIGH7.6CVSS v3
—CVSS v2
0.21%
EPSS (exploit probability)
CWE-918CWE
Description
OpenClaw before 2026.4.8 contains a server-side request forgery policy bypass vulnerability allowing attackers to trigger navigations bypassing normal SSRF checks. Attackers can exploit browser interactions to bypass SSRF protections and access restricted resources.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Affected routers (0)
No routers currently mapped to this CVE in our database.