CVE-2026-28458 Details
Description
OpenClaw version 2026.1.20 prior to 2026.2.1 contains a vulnerability in the Browser Relay (extension must be installed and enabled) /cdp WebSocket endpoint in which it does not require authentication tokens, allowing websites to connect via loopback and access sensitive data. Attackers can exploit this by connecting to ws://127.0.0.1:18792/cdp to steal session cookies and execute JavaScript in other browser tabs.
A vulnerability exists in OpenClaw versions 2026.1.20 prior to 2026.2.1, specifically within the Browser Relay feature of the Chrome extension. The issue arises in the '/cdp' WebSocket endpoint, which does not require authentication tokens. This lack of authentication allows websites to connect to the local relay via loopback and access sensitive data, such as session cookies from other open tabs, and execute JavaScript in those tabs. The vulnerability can be exploited by connecting to 'ws://127.0.0.1:18792/cdp' (the default WebSocket port) to steal cookies and run scripts in the context of other browser tabs.
Users can update to OpenClaw version 2026.2.1 or later, which includes the necessary authentication requirement for the Browser Relay WebSocket endpoint. If an immediate update is not possible, users should disable the Browser Relay extension and avoid visiting untrusted websites.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openclaw openclaw | >= 2026.1.20, < 2026.2.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 9, 2026 | Initial Analysis | [email protected] |
| Mar 6, 2026 | CVE Modified | [email protected] |
| Mar 5, 2026 | New CVE Received | [email protected] |