High severity8.3NVD Advisory· Published Sep 26, 2026
CVE-2026-100589
CVE-2026-100589
Description
OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions to access paired node browser actions despite allowHostControl=false configuration. Attackers with control over sandboxed agent input can select a paired node and perform host browser operations, inspecting or manipulating the connected browser profile and its authenticated state.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.