CVE-2026-45000: OpenClaw < 2026.4.20 - Server-Side Request Forgery via Browser CDP Profile Creation
OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing to private-network or metadata endpoints that bypass security policies and are later probed during normal profile status operations.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45000?
CVE-2026-45000 is classified as a high severity vulnerability due to its potential for server-side request forgery attacks.
How do I fix CVE-2026-45000?
To fix CVE-2026-45000, update OpenClaw to version 2026.4.20 or later.
What is the impact of CVE-2026-45000?
The impact of CVE-2026-45000 includes the possibility for attackers to bypass strict-mode SSRF policy checks and access private networks.
Is CVE-2026-45000 present in all versions of OpenClaw?
CVE-2026-45000 affects all versions of OpenClaw prior to 2026.4.20.
What types of attacks can exploit CVE-2026-45000?
CVE-2026-45000 can be exploited through server-side request forgery attacks that leverage browser CDP profile creation.