Skip to main content
EPSS 0.2%top 91%

Openclaw cli: OpenClaw: iOS A2UI bridge trusted generic local-network pages for agent.request dispatch (CVE-2026-41398)

0
Medium
Published: 08/13/2026 (08/13/2026, 17:21:32 UTC)
Source: GCVE Database
Product: openclaw-cli

Description

OpenClaw CLI versions before 2026.4.2 have a vulnerability in the iOS A2UI bridge that treats generic local-network pages as trusted origins. This allows attacker-controlled pages loaded from local-network or tailnet hosts to dispatch agent.request actions without stricter origin checks. The vulnerability enables injection of unauthorized non-owner agent.request runs into active iOS node sessions, affecting session state and resource consumption. Owner-only actions or arbitrary host execution were not demonstrated. The issue is patched in version 2026.4.2.

CVSS v4.0

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
Low
Vuln. Availability
Low
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

Affected software

Homebrewmore threats →ghsa
openclaw-cli
pkg:brew/openclaw-cli
Affected versions
>=2026.1.29 <2026.4.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/04/2026, 13:18:48 UTC

Technical Analysis

Before OpenClaw 2026.4.2, the iOS A2UI bridge incorrectly trusted generic local-network pages as valid bridge origins, allowing pages from local-network or tailnet hosts to trigger agent.request dispatch without the stricter trusted-canvas origin verification. This flaw permits an attacker-controlled page to inject unauthorized non-owner agent.request operations into an active iOS node session, leading to session state pollution and budget consumption. The vulnerability does not allow owner-only actions or arbitrary code execution on the host. The vulnerability affects openclaw npm package versions from 2026.1.29 up to but not including 2026.4.2. The issue is fixed by restricting A2UI action dispatch to trusted canvas URLs in commit 49d08382a90f71dabe2877b3f6729ad85f808d57.

Potential Impact

An attacker controlling a page loaded from a local-network or tailnet host can inject unauthorized non-owner agent.request commands into an active iOS node session. This can corrupt session state and consume operational budget. However, the vulnerability does not permit execution of owner-only actions or arbitrary code on the host system.

Mitigation Recommendations

A patch is available in OpenClaw version 2026.4.2 that restricts A2UI action dispatch to trusted canvas URLs, eliminating the vulnerability. Users should upgrade to version 2026.4.2 or later once it is published. Until then, caution is advised when loading pages from local-network or tailnet hosts in affected versions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
BREW-openclaw-cli-CVE-2026-41398
Osv Schema Version
1.7.3
Ecosystems
["Homebrew"]
Cvss Version
4.0

Threat ID: 6ac245d612601ec6a316808f

Added to database: 10/04/2026, 12:25:58 UTC

Last enriched: 10/04/2026, 13:18:48 UTC

Last updated: 10/04/2026, 16:08:38 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses