🛡️ CVE Monitor
Dịch vụ / phần mềm liên quan: Node.js / npm

Mô tả

OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control when it is reached through the node.invoke method, although direct browser.request access requires administrator scope. In Gateway deployments that honor caller identity and narrower operator scopes, a write-scoped caller with access to a connected browser-capable node can inspect pages, navigate tabs, or interact with browser-visible applications without the configured admin requirement; practical impact depends on the browser profile and signed-in state. Shared-secret token and password callers are considered fully trusted operators under OpenClaw's security model and are not affected. The issue is fixed in 2026.7.1.

Chi tiết

Trạng tháiDeferred
Điểm CVSS8.3 (v3.1)
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Ngày công bố10:17 26/09/2026
Ngày cập nhật22:18 28/09/2026
Nguồn dữ liệunvd

CWE

  • CWE-863

Sản phẩm bị ảnh hưởng

Nguồn dữ liệu chưa cung cấp thông tin sản phẩm chi tiết.

Tài liệu tham khảo

Lịch sử thay đổi

Thời gianLoạiTrườngGiá trị cũGiá trị mới
22:27 28/09/2026 CREATED cve HIGH

Tất cả thời gian trên trang này hiển thị theo giờ Việt Nam (GMT+7).