Vulnerability  ·  2026-10-01

OpenClaw Windows Node canvas.present SSRF bypass of canvas.navigate URL risk evaluation

VulnerabilityLow impactGlobalCVE-2026-101883
Companion to the 09-30 OpenClaw Windows Node batch; a capability-level SSRF where one canvas method bypasses the URL guard of another. No known exploit.
WebView-based agent display surfaces create a local browser SSRF channel; bypassing the risk check lets agent-steered content reach internal services the policy was designed to protect.
The canvas.present capability renders/navigates URLs without the risk evaluation enforced in canvas.navigate, enabling WebView requests to local/internal targets (SSRF).
OpenClaw Windows Node through 2026.9.4
Upgrade OpenClaw Windows Node beyond 2026.9.4.
NVDOpenClaw CanvasWindow source
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →