CVE-2026-28458Disclosure(openclaw / openclaw)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw version 2026.1.20 prior to 2026.2.1 contains a vulnerability in the Browser Relay (extension must be installed and enabled) /cdp WebSocket endpoint in which it does not require authentication tokens, allowing websites to connect via loopback and access sensitive data. Attackers can exploit this by connecting to ws://127.0.0.1:18792/cdp to steal session cookies and execute JavaScript in other browser tabs.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-07); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-07: 2Mentions · 2026-03-18: 1Patch / Workaround · 2026-03-18: 1Technical Details · 2026-03-07: 1Technical Details · 2026-03-18: 103-0703-18
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-072
Disclosure1General1
2026-03-181
Patch1
Full discourse3 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-28458 - High OpenClaw version 2026.1.20 prior to 2026.2.1 contains a vulnerability in the Browser Relay (extension must be installed and enabled) /cdp WebSocket endpoint in which it does not require authe... https://www.thehackerwire.com/vulnerability/CVE-2026-28458/ https://t.co/b31F7dX1CC

    Post summary

    The tweet announces CVE-2026-28458 as a high‑severity flaw in OpenClaw’s Browser Relay WebSocket endpoint, noting that it bypasses authentication; no PoC, exploit code, or active exploitation evidence is provided.

    0001058
    128 followersView on X
  • rwsanders@rwsanders
    Patch

    and other people's unfavorite are kool-aid stains on a white T-Shirt. Known OpenClaw Security Issues (as of 18 Mar 2026; core engine hardened via patches in 2026.1.29–2026.3.x, but risks persist) Remote Code Execution & Command Injection: CVE-2026-25253 (CVSS 8.8, 1-click via UI token exfil/WebSocket), CVE-2026-24763 (Docker PATH/cmd injection), CVE-2026-25157 (OS command injection), plus workspace/plugin auto-discovery. Authentication & Authorization Failures: Multiple auth bypasses, scope escalation, CSRF, missing webhook validation, CVE-2026-28458 (browser relay), CVE-2026-32302 (trusted-proxy admin access). Denial of Service & Forgery: CVE-2026-28478 (webhook exhaustion), SSRF, unbounded buffering. Data Disclosure & Leaks: Plaintext API keys/credentials, local file disclosure (MEDIA tokens), cross-session exfil via prompt injection. Supply-Chain (ClawHub / ClawHavoc): 341–1,184+ malicious skills delivering stealers (Atomic Stealer, crypto/key loggers); 13.4–36.8% of scanned skills contain critical flaws; unvetted marketplace runs with full agent privileges. Exposure & Defaults: 30k–42k+ publicly exposed instances (default 0.0.0.0 bind, weak/no auth early versions). Other: Sandbox bypasses, memory poisoning, fake GitHub installers with infostealers, prompt-injection-driven unauthorized actions. Known Shortcomings (security-adjacent + functional) Insecure-by-default early design + over-privileged agent model. Impractical manual skill vetting (Lucas-highlighted scalability gap). Unpredictable autonomy (reasoning loops, task drift, stalls, silent/false completions). Steep setup & secure-configuration curve (CLI-heavy, not beginner-friendly). High resource/maintenance burden (frequent patches, memory tuning, 24/7 isolation required). Dependency on external LLMs + evolving unvetted ecosystem. Recommended immediate mitigations (actionable): Run in VM/Docker with no internet except vetted LLM endpoints; never expose publicly; install only from official/pinned verified ClawHub tier; enable any built-in VirusTotal scanning; update to latest 2026.3.x; monitor GitHub advisories.

    Post summary

    The post enumerates multiple CVEs in OpenClaw, detailing their severity and technical characteristics, while highlighting that patches and mitigations are available in the 2026.x releases.

    00000188
    282 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-28458 OpenClaw version 2026.1.20 prior to 2026.2.1 contains a vulnerability in the Browser Relay (extension must be installed and enabled) /cdp WebSocket endpoint in which … https://www.cve.org/CVERecord?id=CVE-2026-28458

    Post summary

    The post merely references CVE‑2026‑28458 with a brief mention of affected OpenClaw versions and a link to the CVE record, providing no further technical details, PoC, exploit code, or mitigation information.

    00000194
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more