CVE-2026-17458

Source
https://cve.org/CVERecord?id=CVE-2026-17458
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-17458.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-17458
Published
2026-07-26T09:45:09.775Z
Modified
2026-08-12T03:51:44.041456851Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
mf-yang openclaw-cn Browser Control HTTP API agent.act.ts clickViaPlaywright server-side request forgery
Details

A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP API. Performing a manipulation results in server-side request forgery. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/17xxx/CVE-2026-17458.json"
}
References

Affected packages

Git / github.com/mf-yang/openclaw-cn

Affected ranges

Type
GIT
Repo
https://github.com/mf-yang/openclaw-cn
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.2.0"
        },
        {
            "last_affected": "0.2.0"
        },
        {
            "introduced": "0.2.1"
        },
        {
            "last_affected": "0.2.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.2.0
0.2.1
v0.*
v0.2.0
v0.2.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-17458.json"