CVE-2026-35673: OpenClaw < 2026.4.29 - SSRF Policy Bypass via Browser Debug/Export Routes
OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows reuse of already-open blocked tabs. Attackers with access to these routes can bypass private-network SSRF policies by reusing blocked tabs to export or inspect content that should remain protected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.4.29 - Configuration
Disable the browser debug and export routes in OpenClaw until the application is upgraded to 2026.4.29 to prevent reuse of blocked tabs.
OpenClaw browser_debug_and_export_routes_enabled = false - Compensating control
Restrict access to the browser debug and export routes to trusted administrators/IPs (via firewall, reverse proxy, ACLs, or WAF) until OpenClaw is upgraded to 2026.4.29.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35673?
The severity of CVE-2026-35673 is classified as medium with a score of 5.9.
How do I fix CVE-2026-35673?
To fix CVE-2026-35673, upgrade OpenClaw to version 2026.4.29 or later.
What type of vulnerability is CVE-2026-35673?
CVE-2026-35673 is a Server-Side Request Forgery (SSRF) policy bypass vulnerability.
What can attackers do with CVE-2026-35673?
Attackers can exploit CVE-2026-35673 to bypass private-network SSRF policies and access restricted content.
Which software is affected by CVE-2026-35673?
CVE-2026-35673 affects OpenClaw versions prior to 2026.4.29.