CVE-2026-62227: OpenClaw 2026.4.14 < 2026.5.26 SSRF via Browser Snapshot
Published Jul 17, 2026
·Updated
OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that fail to validate post-navigation destinations. Attackers with lower-trust access can bypass OpenClaw policy checks to reach network destinations that should have been blocked.
Affected Software
2 affected components
OpenClaw>2026.4.14<2026.5.26
OpenClaw Openclaw Node.js>=2026.4.14<2026.5.26
Event History
Jul 17, 2026
CVE Published
via MITRE·12:07 AM
Data Sourced
via MITRE·12:07 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:18 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-62227?
The severity of CVE-2026-62227 is rated medium with a score of 4.9.
2
How do I fix CVE-2026-62227?
To fix CVE-2026-62227, upgrade OpenClaw to version 2026.5.26 or later, which addresses the SSRF vulnerability.
3
What type of vulnerability is associated with CVE-2026-62227?
CVE-2026-62227 is identified as a server-side request forgery (SSRF) vulnerability.
4
Who is affected by CVE-2026-62227?
Users of OpenClaw versions 2026.4.14 and earlier are affected by CVE-2026-62227.
5
What can attackers do with CVE-2026-62227?
Attackers can exploit CVE-2026-62227 to bypass OpenClaw policy checks and access restricted network destinations.