CVE-2026-42436 POC (Proof-of-Concept)

CVE-2026-42436 POC (Proof-of-Concept)

OpenClaw before 2026.4.14 contains an improper access control vulnerability in browser snapshot, screenshot, and tab routes that fail to consistently validate the final browser target after navigation. Authenticated callers can bypass SSRF restrictions to expose internal or disallowed page content by exploiting route-driven navigation without proper policy re-validation.

Published: 2026-05-05

CVSS: 7.7

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Download CVE-2026-42436 POC (Proof-of-Concept) here:

Tip: Download official Tor Browser at https://www.torproject.org/download/ to access .onion links.

https://hokyo.gr/poc-67-cve-2026-31766/

https://hokyo.gr/poc-294-cve-2026-42233/

https://hokyo.gr/poc-540-cve-2026-41286/

https://hokyo.gr/poc-180-cve-2026-4060/

https://hokyo.gr/poc-568-cve-2026-7898/

Copyright 2017- 2025 Hokyo JapanEats ©