CVE-2026-41347: OpenClaw < 2026.3.31 - Cross-Site Request Forgery via Missing Browser-Origin Validation in HTTP Operator Endpoints
OpenClaw before 2026.3.31 lacks browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mode, allowing cross-site request forgery attacks. Attackers can exploit this by sending malicious requests from a browser in trusted-proxy deployments to perform unauthorized actions on HTTP operator endpoints.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41347?
CVE-2026-41347 is classified as a high-severity vulnerability due to its potential for cross-site request forgery attacks.
How do I fix CVE-2026-41347?
To remediate CVE-2026-41347, upgrade OpenClaw to version 2026.3.31 or later, which includes necessary browser-origin validations.
What types of attacks can CVE-2026-41347 facilitate?
CVE-2026-41347 can facilitate cross-site request forgery (CSRF) attacks due to the lack of browser-origin validation in HTTP operator endpoints.
Which versions of OpenClaw are affected by CVE-2026-41347?
CVE-2026-41347 affects all versions of OpenClaw prior to 2026.3.31.
In what mode does CVE-2026-41347 become a risk?
CVE-2026-41347 poses a risk when OpenClaw is operating in trusted-proxy mode without proper browser-origin validation.