Goal Reached Thanks to every supporter โ€” we hit 100%!

Goal: 1000 CNY ยท Raised: 1359 CNY

100%

CVE-2026-43575 โ€” AI Deep Analysis Summary

CVSS 9.8 ยท Critical

Q1What is this vulnerability? (Essence + Consequences)

๐Ÿšจ **Essence**: OpenClaw's sandbox noVNC helper route lacks proper auth checks. <br>๐Ÿ’ฅ **Consequences**: Attackers bypass bridge auth to access interactive browser sessions. Credentials are exposed.โ€ฆ

Q2Root Cause? (CWE/Flaw)

๐Ÿ›ก๏ธ **CWE-862**: Missing Authorization. <br>๐Ÿ” **Flaw**: The noVNC helper route does not verify user identity before granting access. It trusts the request blindly.

Q3Who is affected? (Versions/Components)

๐Ÿ“ฆ **Vendor**: OpenClaw. <br>๐Ÿ“‰ **Affected**: Versions **before 2026.4.10**. <br>โš ๏ธ **Includes**: Version 2026.2.21 and all prior releases.

Q4What can hackers do? (Privileges/Data)

๐Ÿ‘ค **Privileges**: Unauthorized access to sandboxed browser sessions. <br>๐Ÿ“‚ **Data**: Full visibility of interactive browser UI. Potential credential theft from exposed sessions.

Q5Is exploitation threshold high? (Auth/Config)

๐Ÿ“‰ **Threshold**: **LOW**. <br>๐Ÿ”‘ **Auth**: None required. <br>๐ŸŒ **Config**: Network accessible (AV:N). No user interaction needed (UI:N). Easy remote exploitation.

Q6Is there a public Exp? (PoC/Wild Exploitation)

๐Ÿšซ **Public Exp**: No PoC listed in data. <br>๐ŸŒ **Wild Exp**: Unconfirmed. <br>๐Ÿ“ **Note**: VulnCheck advisory exists, but code-level exploit is not public yet.

Q7How to self-check? (Features/Scanning)

๐Ÿ” **Check**: Scan for OpenClaw instances. <br>๐Ÿงช **Test**: Attempt direct access to noVNC helper routes without authentication tokens. <br>๐Ÿ“Š **Indicator**: Look for version strings < 2026.4.10.

Q8Is it fixed officially? (Patch/Mitigation)

โœ… **Fixed**: Yes. <br>๐Ÿ”ง **Patch**: Version **2026.4.10** or later. <br>๐Ÿ”— **Ref**: GitHub Security Advisory GHSA-92jp-89mq-4374. Commit 8dfbf32 fixes it.

Q9What if no patch? (Workaround)

๐Ÿ›‘ **Workaround**: Isolate the sandbox network. <br>๐Ÿšซ **Block**: Restrict access to noVNC helper routes via firewall/WAF. <br>๐Ÿ‘€ **Monitor**: Alert on unauthorized access attempts to these endpoints.

Q10Is it urgent? (Priority Suggestion)

๐Ÿ”ฅ **Priority**: **CRITICAL**. <br>๐Ÿ“ˆ **CVSS**: 9.1 (High). <br>โšก **Action**: Patch immediately. Low barrier to entry + high impact (full session compromise) = urgent remediation needed.