CVE-2026-100589: OpenClaw before 2026.7.1 Sandbox Bypass via Browser Node
OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions to access paired node browser actions despite allowHostControl=false configuration. Attackers with control over sandboxed agent input can select a paired node and perform host browser operations, inspecting or manipulating the connected browser profile and its authenticated state.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.7.1
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs control over input supplied to a sandboxed agent session. Exploitation also depends on the availability of a paired node that the attacker can select for browser actions.
Does setting allowHostControl=false prevent exploitation?
No. The vulnerability allows sandboxed sessions to access paired node browser actions despite allowHostControl=false.
What could an attacker do after exploiting it?
An attacker can perform browser operations on the host through a paired node. This may let them inspect or manipulate the connected browser profile and its authenticated state.
Which deployments should be prioritized for remediation?
Prioritize OpenClaw deployments before 2026.7.1 that run sandboxed agents with attacker-controlled or untrusted input and have paired nodes available for browser actions.