#VU126427 Improper access control in OpenClaw
Published: April 17, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in browser snapshot, screenshot, and tab routes when handling route-driven navigation. A remote user can use crafted snapshot, screenshot, or tab requests to disclose sensitive information.
This issue affects restrictive browser SSRF configurations and can expose content from internal or otherwise disallowed pages.