Openclaw cli: OpenClaw: iOS A2UI bridge trusted generic local-network pages for agent.request dispatch (CVE-2026-41398)
Description
OpenClaw CLI versions before 2026.4.2 have a vulnerability in the iOS A2UI bridge that treats generic local-network pages as trusted origins. This allows attacker-controlled pages loaded from local-network or tailnet hosts to dispatch agent.request actions without stricter origin checks. The vulnerability enables injection of unauthorized non-owner agent.request runs into active iOS node sessions, affecting session state and resource consumption. Owner-only actions or arbitrary host execution were not demonstrated. The issue is patched in version 2026.4.2.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Before OpenClaw 2026.4.2, the iOS A2UI bridge incorrectly trusted generic local-network pages as valid bridge origins, allowing pages from local-network or tailnet hosts to trigger agent.request dispatch without the stricter trusted-canvas origin verification. This flaw permits an attacker-controlled page to inject unauthorized non-owner agent.request operations into an active iOS node session, leading to session state pollution and budget consumption. The vulnerability does not allow owner-only actions or arbitrary code execution on the host. The vulnerability affects openclaw npm package versions from 2026.1.29 up to but not including 2026.4.2. The issue is fixed by restricting A2UI action dispatch to trusted canvas URLs in commit 49d08382a90f71dabe2877b3f6729ad85f808d57.
Potential Impact
An attacker controlling a page loaded from a local-network or tailnet host can inject unauthorized non-owner agent.request commands into an active iOS node session. This can corrupt session state and consume operational budget. However, the vulnerability does not permit execution of owner-only actions or arbitrary code on the host system.
Mitigation Recommendations
A patch is available in OpenClaw version 2026.4.2 that restricts A2UI action dispatch to trusted canvas URLs, eliminating the vulnerability. Users should upgrade to version 2026.4.2 or later once it is published. Until then, caution is advised when loading pages from local-network or tailnet hosts in affected versions.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-openclaw-cli-CVE-2026-41398
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 4.0
Threat ID: 6ac245d612601ec6a316808f
Added to database: 10/04/2026, 12:25:58 UTC
Last enriched: 10/04/2026, 13:18:48 UTC
Last updated: 10/04/2026, 16:08:38 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.