CVE-2026-22174

MEDIUM5.7EPSS 0.03%

OpenClaw Loopback CDP probe can leak Gateway token to local listener

發布日:2026/3/3修改日:2026/3/18

描述

### Summary A local process can capture the OpenClaw Gateway auth token from Chrome CDP probe traffic on loopback. ### Details Affected versions inject `x-openclaw-relay-token` for loopback CDP URLs, and CDP reachability probes send that header to `/json/version`. If an attacker controls the probed loopback port, they can read that token and reuse it as Gateway bearer auth. Relevant code paths (pre-fix): - `src/browser/extension-relay.ts` (`getChromeExtensionRelayAuthHeaders`) - `src/browser/cdp.helpers.ts` (`getHeadersWithAuth`) - `src/browser/chrome.ts` (`fetchChromeVersion`) ### Affected Packages / Versions - Package: `openclaw` (npm) - Latest published (at triage): `2026.2.21-2` - Vulnerable: `<= 2026.2.21-2` - Patched: >= 2026.2.22 ### Deployment Model Applicability This does **not** change OpenClaw’s documented security model for standard single-owner installs (you own the machine/VPS and trust local processes under that OS account boundary). Risk is for **non-standard shared-user/shared-host installs** where an untrusted local user/process can race/bind the loopback relay port. ### Impact - Local credential disclosure. - Follow-on impact depends on local deployment and enabled Gateway capabilities. ### Fix Commit(s) - `afa22acc4a09fdf32be8a167ae216bee85c30dad` ### Release Process Note Patched version is set to >= 2026.2.22 for the published release. OpenClaw thanks @tdjackey for reporting.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.7CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N

參考連結(5)