Switch language한국어
Back to the list

GHSA-92JP-89MQ-4374: Unauthenticated Sandbox Access and Context Leakage in OpenClaw

TL;DR AI

Key summary

2 min read
  1. OpenClaw had a critical authentication flaw in versions before 2026.4.9.

  2. A middleware ordering issue and sensitive data exposure let unauthenticated attackers bypass controls and reach sandboxed browser sessions through noVNC.

  3. The bug, tracked as GHSA-92JP-89MQ-4374, carries CVSS 9.8 and maps to CWE-287 and CWE-200.

  4. A proof of concept exists, and the issue is fixed in OpenClaw 2026.4.9.

Read the original