CyberRota Analysis
AI-GeneratedThe vulnerability in the mf-yang openclaw-cn up to version 0.2.1 affects the Browser Control HTTP API, specifically the clickViaPlaywright function, allowing for server-side request forgery (SSRF) attacks. This flaw can be exploited remotely, posing a risk to any systems utilizing this component. Organizations using this software should prioritize patching to mitigate potential exploitation, especially given the public disclosure of the vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP API. Performing a manipulation results in server-side request forgery. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.