CyberRota Analysis
AI-GeneratedOpenClaw versions prior to 2026.7.1 are vulnerable to a sandbox bypass that permits unauthorized access to paired node browser actions, even when the allowHostControl setting is disabled. This flaw enables attackers controlling sandboxed agent input to manipulate the host browser, potentially compromising sensitive data and authenticated sessions. Organizations utilizing OpenClaw should prioritize patching this vulnerability to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions to access paired node browser actions despite allowHostControl=false configuration. Attackers with control over sandboxed agent input can select a paired node and perform host browser operations, inspecting or manipulating the connected browser profile and its authenticated state.