


Perceptive Security
SOC/SIEM Consultancy

OpenClaw before 2026.3.31 lacks browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mode, allowing cross-site request forgery a…
Published:
22 April 2026 at 22:00:00
Alert date:
23 April 2026 at 23:04:51
Source:
nvd.nist.gov
Web Technologies
OpenClaw versions before 2026.3.31 contain a cross-site request forgery vulnerability due to missing browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mode. This security flaw allows attackers to send malicious requests from browsers in trusted-proxy deployments, enabling them to perform unauthorized actions on HTTP operator endpoints. The vulnerability affects the security of OpenClaw installations using trusted-proxy configurations and could lead to unauthorized access or manipulation of system operations.
Technical details
Mitigation steps:
Affected products:
OpenClaw
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-41347
https://github.com/openclaw/openclaw/commit/6b3f99a11f4d070fa5ed2533abbb3d7329ea4f0d
https://github.com/openclaw/openclaw/security/advisories/GHSA-mhr7-2xmv-4c4q
https://www.vulncheck.com/advisories/openclaw-cross-site-request-forgery-via-missing-browser-origin-validation-in-http-operator-endpoints
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
