Sandbox noVNC helper route exposed interactive browser session credentials.
openclaw>= 2026.2.21 < 2026.4.10>= 2026.4.10The sandbox noVNC helper route could be reached without the intended bridge authentication, exposing an interactive browser session surface.
The fix gates the sandbox noVNC helper route behind bridge authentication.
The issue was fixed in #63882. The first stable tag containing the fix is v2026.4.10, and openclaw@2026.4.14 includes the fix.
8dfbf3268bd224b7377d1ecca77a445100746085Users should upgrade to openclaw 2026.4.10 or newer. The latest npm release, 2026.4.14, already includes the fix.
Thanks to @zsxsoft, with sponsorship from @KeenSecurityLab and @qclawer for reporting this issue.
{
"github_reviewed": true,
"github_reviewed_at": "2026-04-17T20:08:01Z",
"cwe_ids": [
"CWE-306"
],
"severity": "MODERATE",
"nvd_published_at": null
}