Security Advisory
CVE-2026-62197
8.5
HIGH
Vulnerability Description
OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket URLs. Attackers with lower-trust access can reach network destinations that should have been blocked by OpenClaw policy when the affected feature is enabled.
Published Date
July 13, 2026
Official Source
NIST NVD Advisory