Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rj2p-j66c-mgqh | OpenClaw: Browser tabs action select and close routes bypassed SSRF policy |
Thu, 07 May 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-918 |
Tue, 05 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 05 May 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in the browser tabs action select and close routes. Attackers can bypass configured browser SSRF policy protections by exploiting the /tabs/action endpoint to perform unauthorized tab navigation operations. | |
| Title | OpenClaw < 2026.4.10 - SSRF Policy Bypass in Browser Tabs Action Routes | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-05T14:12:42.708Z
Reserved: 2026-04-27T11:40:07.152Z
Link: CVE-2026-42439
Updated: 2026-05-05T14:04:01.160Z
Status : Analyzed
Published: 2026-05-05T12:16:18.490
Modified: 2026-05-07T01:59:18.467
Link: CVE-2026-42439
No data.
OpenCVE Enrichment
Updated: 2026-05-07T04:15:21Z
Github GHSA