


Perceptive Security
SOC/SIEM Consultancy

OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that exposes Chrome DevTools Protocol on 0.0.0.0. …
Published:
5 May 2026 at 22:00:00
Alert date:
6 May 2026 at 23:05:11
Source:
nvd.nist.gov
Web Technologies, Security Tools
OpenClaw before version 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay. The vulnerability exposes Chrome DevTools Protocol on 0.0.0.0, allowing attackers to access the DevTools protocol outside intended local sandbox boundaries. This is caused by an overly broad binding configuration in the CDP relay component. The vulnerability affects the security boundaries of the sandbox environment and could allow unauthorized remote access to debugging capabilities.
Technical details
Mitigation steps:
Affected products:
OpenClaw
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-43581
https://github.com/openclaw/openclaw/commit/fbf11ebdb7110632f93926d0ac7b48f04cb44d77
https://github.com/openclaw/openclaw/security/advisories/GHSA-525j-hqq2-66r4
https://www.vulncheck.com/advisories/openclaw-chrome-devtools-protocol-exposure-via-overly-broad-cdp-relay-binding
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
