Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xmv5-r8v7-g6g5

Опубликовано: 06 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9
CVSS3: 9.6

Описание

OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that exposes Chrome DevTools Protocol on 0.0.0.0. Attackers can access the DevTools protocol outside intended local sandbox boundaries by exploiting the overly broad binding configuration.

OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that exposes Chrome DevTools Protocol on 0.0.0.0. Attackers can access the DevTools protocol outside intended local sandbox boundaries by exploiting the overly broad binding configuration.

EPSS

Процентиль: 12%
0.00214
Низкий

9 Critical

CVSS4

9.6 Critical

CVSS3

Дефекты

CWE-1188

Связанные уязвимости

CVSS3: 9.6
nvd
3 месяца назад

OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that exposes Chrome DevTools Protocol on 0.0.0.0. Attackers can access the DevTools protocol outside intended local sandbox boundaries by exploiting the overly broad binding configuration.

EPSS

Процентиль: 12%
0.00214
Низкий

9 Critical

CVSS4

9.6 Critical

CVSS3

Дефекты

CWE-1188