Browser interaction routes could pivot into local CDP and regain file reads.
openclaw< 2026.4.9>= 2026.4.9Browser act/evaluate interactions could trigger navigation into the local CDP origin and then create or read disallowed file:// pages despite direct navigation guards.
The fix re-checks browser URLs after interaction-driven navigations and blocks targets that violate the configured navigation policy.
The issue was fixed in #63226. The first stable tag containing the fix is v2026.4.9, and openclaw@2026.4.14 includes the fix.
5f5b3d733bdd791cb457f838514179e1288b10b3Users should upgrade to openclaw 2026.4.9 or newer. The latest npm release, 2026.4.14, already includes the fix.
Thanks to @tdjackey for reporting this issue.
{
"cwe_ids": [
"CWE-693"
],
"github_reviewed": true,
"github_reviewed_at": "2026-04-17T22:14:20Z",
"nvd_published_at": null,
"severity": "MODERATE"
}