CVE-2026-41372
OpenClaw before 2026.4.2 fails to normalize trailing-dot localhost hosts in remote CDP discovery responses, allowing bypass of loopback prot
CVSS
5.8
Medium
EPSS
0.3%
p16
KEV
—
Exploit Today
5
0-100
Published: Apr 28, 2026 · Last modified: Jul 24, 2026 · CWE-639
0.3%EPSS · 30 days0.3%
2026-07-312026-08-28
OpenClaw before 2026.4.2 fails to normalize trailing-dot localhost hosts in remote CDP discovery responses, allowing bypass of loopback protections. Attackers can craft hostile discovery responses returning localhost. to retarget authenticated browser control toward localhost endpoints and expose browser state.
- github.comhttps://github.com/openclaw/openclaw/commit/9c22d636697336a6b22b0ae24798d8b8325d7828
- github.comhttps://github.com/openclaw/openclaw/security/advisories/GHSA-fh32-73r9-rgh5
- www.vulncheck.comhttps://www.vulncheck.com/advisories/openclaw-loopback-protection-bypass-via-trailing-dot-localhost-in-cdp-discovery
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-192946.4 MED—
——0IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute and read any user's private flow due to improper authorization.1dCVE-2026-189048.2 HIG—
——0IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized messages due to a namespace collision between user identifiers.1dCVE-2026-822905.3 MED—
——0Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints. Authenticated attackers can delete or modify other users' feedback by supplying arbitrary feedback identifiers, corrupting human-rating data used for model evaluation.1dCVE-2026-822848.1 HIG—
——0Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/answer endpoints. Authenticated attackers can read other users' conversation histories including private knowledge base content, delete arbitrary chats, and inject fabricated messages into other users' conversations.1dCVE-2026-822838.1 HIG—
——0VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users to access other users' conversations. Attackers can read, modify, and delete arbitrary conversations and messages by supplying caller-controlled identifiers to memory endpoints.1dCVE-2026-822817.4 HIG—
——0Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py. Attackers can read other users' chat histories, delete conversations, or rename conversations by supplying arbitrary conversation identifiers without proper authorization checks.1d