๐Ÿ” CVE Alert

CVE-2026-101883

MEDIUM 5.4

OpenClaw Windows Node through 2026.9.4 SSRF via canvas.present

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability that bypasses URL risk evaluation enforced by canvas.navigate. Attackers with gateway or agent access can issue canvas.present to make the node's WebView send requests to localhost, private networks, or tailnet services from the user's machine.

CWE CWE-918
Vendor openclaw
Product openclaw windows node
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for openclaw openclaw windows node

Be the first to know when new medium vulnerabilities affecting openclaw openclaw windows node are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

OpenClaw / OpenClaw Windows Node
0 โ‰ค 2026.9.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/openclaw/openclaw-windows-node/security/advisories/GHSA-7vch-pmw9-3g4q github.com: https://github.com/openclaw/openclaw-windows-node/commit/16528aadaa45d7bc6718b07ccf8b01f3eb033ad1 github.com: https://github.com/openclaw/openclaw-windows-node/blob/v2026.9.4/src/OpenClaw.Tray.WinUI/Services/NodeService.cs#L1244-L1270 github.com: https://github.com/openclaw/openclaw-windows-node/blob/v0.6.12/src/OpenClaw.Tray.WinUI/Windows/CanvasWindow.xaml.cs#L77-L109 vulncheck.com: https://www.vulncheck.com/advisories/openclaw-windows-node-through-2026.9.4-ssrf-via-canvas-present

Credits

Cameron Beeley (anagnorisis2peripeteia)