OpenClaw: Sandbox noVNC helper route exposed interactive browser session credentials
Moderate severity
GitHub Reviewed
Published
Apr 16, 2026
in
openclaw/openclaw
•
Updated Apr 17, 2026
Description
Published to the GitHub Advisory Database
Apr 17, 2026
Reviewed
Apr 17, 2026
Last updated
Apr 17, 2026
Summary
Sandbox noVNC helper route exposed interactive browser session credentials.
Affected Packages / Versions
openclaw>= 2026.2.21 < 2026.4.10>= 2026.4.10Impact
The sandbox noVNC helper route could be reached without the intended bridge authentication, exposing an interactive browser session surface.
Technical Details
The fix gates the sandbox noVNC helper route behind bridge authentication.
Fix
The issue was fixed in #63882. The first stable tag containing the fix is
v2026.4.10, andopenclaw@2026.4.14includes the fix.Fix Commit(s)
8dfbf3268bd224b7377d1ecca77a445100746085Release Process Note
Users should upgrade to
openclaw2026.4.10 or newer. The latest npm release,2026.4.14, already includes the fix.Credits
Thanks to @zsxsoft, with sponsorship from @KeenSecurityLab and @qclawer for reporting this issue.
References