HTTP operator endpoints lack browser-origin validation in trusted-proxy mode
openclaw (npm)2026.3.31<=2026.3.28>= 2026.3.31v2026.3.316b3f99a11f4d070fa5ed2533abbb3d7329ea4f0d — 2026-03-31T19:49:26+09:00OpenClaw thanks @AntAISecurityLab for reporting.
{
"github_reviewed": true,
"github_reviewed_at": "2026-04-03T02:55:08Z",
"cwe_ids": [
"CWE-346",
"CWE-352"
],
"severity": "LOW",
"nvd_published_at": null
}