
CVE-2026-43576 OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in the CDP /json/version WebSocket endpoint that allows attackers to pivot to untrusted … https://www.cve.org/CVERecord?id=CVE-2026-43576
Post summary
The post announces that OpenClaw prior to 2026.4.5 has a server‑side request forgery vulnerability in its CDP /json/version WebSocket endpoint, enabling attackers to pivot to untrusted resources.

