GHSA-w8g9-x8gx-crmm

Suggest an improvement
Source
https://github.com/advisories/GHSA-w8g9-x8gx-crmm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-w8g9-x8gx-crmm/GHSA-w8g9-x8gx-crmm.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-w8g9-x8gx-crmm
Aliases
Downstream
Published
2026-04-09T17:36:59Z
Modified
2026-05-06T02:51:10Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:N CVSS Calculator
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenClaw: Strict browser SSRF bypass in Playwright redirect handling leaves private targets reachable
Details

Impact

Strict browser SSRF bypass in Playwright redirect handling leaves private targets reachable.

Strict browser SSRF checks could miss Playwright request-time navigation to private targets.

OpenClaw is a user-controlled local assistant. This advisory is scoped to the OpenClaw trust model and does not assume a multi-tenant service boundary.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Affected versions: 2026.3.8
  • Patched versions: 2026.4.8

Fix

The issue was fixed on main and is available in the patched npm version listed above. The verified fixed tree is commit d7c3210cd6f5fdfdc1beff4c9541673e814354d5.

Verification

The fix was re-checked against main before publication, including targeted regression tests for the affected security boundary.

Credits

Thanks @smaeljaish771 for reporting.

Database specific
{
    "cwe_ids":  [
        "CWE-918"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-04-09T17:36:59Z",
    "nvd_published_at":  "2026-04-28T19:37:46Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2026.4.8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-w8g9-x8gx-crmm/GHSA-w8g9-x8gx-crmm.json"