This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis โ
Q1What is this vulnerability? (Essence + Consequences)
๐ก๏ธ **CWE-862**: Missing Authorization. <br>๐ **Flaw**: The noVNC helper route does not verify user identity before granting access. It trusts the request blindly.
Q3Who is affected? (Versions/Components)
๐ฆ **Vendor**: OpenClaw. <br>๐ **Affected**: Versions **before 2026.4.10**. <br>โ ๏ธ **Includes**: Version 2026.2.21 and all prior releases.
Q4What can hackers do? (Privileges/Data)
๐ค **Privileges**: Unauthorized access to sandboxed browser sessions. <br>๐ **Data**: Full visibility of interactive browser UI. Potential credential theft from exposed sessions.
Q5Is exploitation threshold high? (Auth/Config)
๐ **Threshold**: **LOW**. <br>๐ **Auth**: None required. <br>๐ **Config**: Network accessible (AV:N). No user interaction needed (UI:N). Easy remote exploitation.
Q6Is there a public Exp? (PoC/Wild Exploitation)
๐ซ **Public Exp**: No PoC listed in data. <br>๐ **Wild Exp**: Unconfirmed. <br>๐ **Note**: VulnCheck advisory exists, but code-level exploit is not public yet.
Q7How to self-check? (Features/Scanning)
๐ **Check**: Scan for OpenClaw instances. <br>๐งช **Test**: Attempt direct access to noVNC helper routes without authentication tokens. <br>๐ **Indicator**: Look for version strings < 2026.4.10.
Q8Is it fixed officially? (Patch/Mitigation)
โ **Fixed**: Yes. <br>๐ง **Patch**: Version **2026.4.10** or later. <br>๐ **Ref**: GitHub Security Advisory GHSA-92jp-89mq-4374. Commit 8dfbf32 fixes it.
Q9What if no patch? (Workaround)
๐ **Workaround**: Isolate the sandbox network. <br>๐ซ **Block**: Restrict access to noVNC helper routes via firewall/WAF. <br>๐ **Monitor**: Alert on unauthorized access attempts to these endpoints.