What happened
Companion to the 09-30 OpenClaw Windows Node batch; a capability-level SSRF where one canvas method bypasses the URL guard of another. No known exploit.
Why it matters
WebView-based agent display surfaces create a local browser SSRF channel; bypassing the risk check lets agent-steered content reach internal services the policy was designed to protect.
Attack vector
The canvas.present capability renders/navigates URLs without the risk evaluation enforced in canvas.navigate, enabling WebView requests to local/internal targets (SSRF).
Affected systems
OpenClaw Windows Node through 2026.9.4
Mitigation
Upgrade OpenClaw Windows Node beyond 2026.9.4.