#VU125284 Incorrect authorization in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a local user to mutate persistent browser profiles.
The vulnerability exists due to improper authorization in node.invoke(browser.proxy) when invoking browser proxy functionality. A local user can invoke this path to mutate persistent browser profiles.
This issue is scoped to the OpenClaw trust model and does not assume a multi-tenant service boundary.