


Perceptive Security
SOC/SIEM Consultancy

OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that exposes Chrome DevTools Protocol on 0.0.0.0. …
Published:
5 May 2026 at 22:00:00
Alert date:
6 May 2026 at 22:04:36
Source:
nvd.nist.gov
Web Technologies, Security Tools
OpenClaw before version 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay. The vulnerability exposes Chrome DevTools Protocol on 0.0.0.0, allowing attackers to access the DevTools protocol outside intended local sandbox boundaries. This occurs due to an overly broad binding configuration that breaks sandbox security boundaries. Attackers can exploit this configuration flaw to gain unauthorized access to debugging capabilities that should be restricted to local access only.
Technical details
Mitigation steps:
Affected products:
OpenClaw
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-43581
https://github.com/openclaw/openclaw/commit/fbf11ebdb7110632f93926d0ac7b48f04cb44d77
https://github.com/openclaw/openclaw/security/advisories/GHSA-525j-hqq2-66r4
https://www.vulncheck.com/advisories/openclaw-chrome-devtools-protocol-exposure-via-overly-broad-cdp-relay-binding
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
