PatchSiren cyber security CVE debrief
CVE-2026-28395 OpenClaw CVE debrief
OpenClaw versions 2026.1.14-1 through 2026.2.11 contain an improper network binding vulnerability in the Chrome extension relay server. When a wildcard cdpUrl is configured, the relay HTTP/WebSocket server incorrectly treats wildcard hosts as loopback addresses, causing it to bind to all network interfaces rather than localhost. This exposes the relay HTTP endpoints to remote attackers, enabling service presence and port information leakage, as well as denial-of-service and brute-force attacks against the relay token header. The vulnerability requires the Chrome extension to be installed and enabled. Two patches have been released to address this issue.
- Vendor
- OpenClaw
- Product
- Unknown
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-05
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-03-05
- Advisory updated
- 2026-05-26
Who should care
Organizations using OpenClaw versions 2026.1.14-1 through 2026.2.11 with the Chrome extension relay server enabled, particularly those with wildcard cdpUrl configurations or exposed Node.js environments. Security teams monitoring for improper network binding vulnerabilities and developers of browser automation tools using CDP (Chrome DevTools Protocol) relay servers.
Technical summary
The OpenClaw Chrome extension relay server contains a binding flaw where wildcard cdpUrl configurations are incorrectly interpreted as loopback addresses. The server uses this configuration to determine its listen address, but fails to validate that wildcard hosts should not bind to all interfaces. This results in the HTTP/WebSocket relay server accepting connections from any network interface, exposing service presence, port information, and the relay token header to remote attackers. The vulnerability is exploitable without authentication and can facilitate reconnaissance, DoS, and brute-force attacks against the relay token mechanism.
Defensive priority
MEDIUM
Recommended defensive actions
- Upgrade OpenClaw to version 2026.2.12 or later
- If immediate patching is not possible, avoid configuring wildcard cdpUrl values in OpenClaw relay server configurations
- Restrict network access to OpenClaw relay server ports using host-based firewall rules to limit exposure
- Monitor for unauthorized access attempts to relay HTTP endpoints on exposed interfaces
- Review Chrome extension relay server configurations to ensure explicit localhost binding is enforced
Evidence notes
CVE published 2026-03-05; modified 2026-05-26. Affected versions: 2026.1.14-1 and later, prior to 2026.2.12. CVSS 4.0 vector: AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N. CWE-1327 (Binding to an Unrestricted IP Address). Two commits identified as patches.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-28395 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-28395
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-28395 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-28395
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/openclaw/openclaw/commit/8d75a496bf5aaab1755c56cf48502d967c75a1d0
[email protected] - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/openclaw/openclaw/commit/a1e89afcc19efd641c02b24d66d689f181ae2b5c
[email protected] - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/openclaw/openclaw/security/advisories/GHSA-qw99-grcx-4pvm
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/openclaw-unintended-public-binding-of-chrome-extension-relay-via-wildcard-cdpurl
[email protected] - Broken Link
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.