Description
OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control HTTP route, allowing unauthorized local callers to invoke privileged operations. Remote attackers on the local network or local processes can execute arbitrary browser-context actions and access sensitive in-session data by sending requests to unauthenticated endpoints.
Problem types
Missing Authentication for Critical Function
Product status
2026.1.5 (custom) before 2026.2.12
Credits
Troy Cusolle (@tcusolle)
References
github.com/...enclaw/security/advisories/GHSA-qpjj-47vm-64pj (GitHub Security Advisory (GHSA-qpjj-47vm-64pj))
github.com/...ommit/9230a2ae14307740a13ada7afd6dcfab34e0287f (Patch Commit)
www.vulncheck.com/...ation-in-browser-control-http-endpoints (VulnCheck Advisory: OpenClaw 2026.1.5 < 2026.2.12 - Missing Authentication in Browser Control HTTP Endpoints)