CVE-2026-62197: OpenClaw < 2026.6.6 Policy Bypass via CDP Discovery
OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket URLs. Attackers with lower-trust access can reach network destinations that should have been blocked by OpenClaw policy when the affected feature is enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.6.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62197?
The severity of CVE-2026-62197 is rated high with a score of 8.5.
How do I fix CVE-2026-62197?
To fix CVE-2026-62197, upgrade OpenClaw to version 2026.6.6 or later.
What type of vulnerability is CVE-2026-62197?
CVE-2026-62197 is classified as a policy bypass vulnerability related to server-side request forgery (SSRF).
What impact does CVE-2026-62197 have on users?
CVE-2026-62197 allows attackers with lower-trust access to reach blocked network destinations.
When was CVE-2026-62197 published?
CVE-2026-62197 was published on July 13, 2026.