{"id":"CVE-2026-41398","aliases":["GHSA-4p4f-fc8q-84m3"],"url":"https://o3.security/vulnerability/CVE-2026-41398","summary":"OpenClaw - Unauthorized Agent Request Dispatch via Untrusted Local-Network Pages in iOS A2UI Bridge","details":"OpenClaw before 2026.4.2 contains an improper access control vulnerability in the iOS A2UI bridge that treats generic local-network pages as trusted origins. Attackers can inject unauthorized agent.request runs by loading attacker-controlled pages from local-network or tailnet hosts, polluting session state and consuming budget.","published":"2026-04-28T18:09:57.031Z","modified":"2026-08-07T11:51:03.443226208Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"openclaw","fixedVersion":"2026.4.2"}],"fix":{"url":"https://github.com/openclaw/openclaw/commit/49d08382a90f71dabe2877b3f6729ad85f808d57","label":"openclaw/openclaw@49d0838"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41398.json"},{"type":"ADVISORY","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-4p4f-fc8q-84m3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41398"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/openclaw-unauthorized-agent-request-dispatch-via-untrusted-local-network-pages-in-ios-a2ui-bridge"},{"type":"FIX","url":"https://github.com/openclaw/openclaw/commit/49d08382a90f71dabe2877b3f6729ad85f808d57"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:51:03.443226208Z"}}