CVE-2026-101883: OpenClaw Windows Node through 2026.9.4 SSRF via canvas.present
Published Sep 30, 2026
·Updated
OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability that bypasses URL risk evaluation enforced by canvas.navigate. Attackers with gateway or agent access can issue canvas.present to make the node's WebView send requests to localhost, private networks, or tailnet services from the user's machine.
Affected Software
1 affected component
OpenClaw Windows Node<=2026.9.4
Event History
Sep 30, 2026
CVE Published
via MITRE·07:16 PM
Data Sourced
via MITRE·07:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker needs gateway or agent access to issue the canvas.present capability. No user interaction is required.
2
What resources could be reached through a successful exploit?
The affected node's WebView can be induced to send requests from the user's machine to localhost, private-network hosts, or tailnet services. This bypasses the URL risk evaluation applied by canvas.navigate.