GHSA-h9g4-589h-68xv

Suggest an improvement
Source
https://github.com/advisories/GHSA-h9g4-589h-68xv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-h9g4-589h-68xv/GHSA-h9g4-589h-68xv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-h9g4-589h-68xv
Aliases
Published
2026-02-18T17:45:31Z
Modified
2026-03-05T22:11:20Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
OpenClaw has an authentication bypass in sandbox browser bridge server
Details

Summary

openclaw could start the sandbox browser bridge server without authentication.

When the sandboxed browser is enabled, openclaw runs a local (loopback) HTTP bridge that exposes browser control endpoints (for example /profiles, /tabs, /tabs/open, /agent/*). Due to missing auth wiring in the sandbox initialization path, that bridge server accepted requests without requiring gateway auth.

Impact

A local attacker (any process on the same machine) could access the bridge server port and:

  • enumerate open tabs and retrieve CDP WebSocket URLs
  • open/close/navigate tabs
  • execute JavaScript in page contexts via CDP
  • exfiltrate cookies/session data and page contents from authenticated sessions

This is a localhost-only exposure (CVSS AV:L), but provides full browser-session compromise for sandboxed browser usage.

Affected Versions

  • Introduced in: 2026.1.29-beta.1 (first npm release that shipped the sandbox browser bridge)
  • Affected range: >=2026.1.29-beta.1 <2026.2.14

Patched Versions

  • 2026.2.14

Mitigation

  • Upgrade to 2026.2.14 (recommended).
  • Or disable the sandboxed browser (agents.defaults.sandbox.browser.enabled=false).

Fix Details

  • The sandbox browser bridge server now always requires auth and enforces the same gateway browser control auth (token/password) that loopback browser clients already use.
  • Additional hardening: bridge server refuses non-loopback binds; local helper servers are bound to loopback.
  • Added regression tests (including unit coverage for per-port bridge auth fallback).

Fix commits:

  • openclaw/openclaw@4711a943e30bc58016247152ba06472dab09d0b0
  • openclaw/openclaw@6dd6bce997c48752134f2d6ed89b27de01ced7e3
  • openclaw/openclaw@cd84885a4ac78eadb7bf321aae98db9519426d67

Credits

Thanks to Adnan Jakati (@jackhax) of Praetorian for reporting this issue.

Database specific
{
    "cwe_ids":  [
        "CWE-306"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-02-18T17:45:31Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
2026.1.29-beta.1
Fixed
2026.2.14

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-h9g4-589h-68xv/GHSA-h9g4-589h-68xv.json"