OpenClaw < 2026.3.22 - Arbitrary Code Execution via Unvalidated WebView JavascriptInterface
Published Apr 10, 2026
8.6
HIGHCVSS 4.0
EPSS 0.54%
Description
OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing attackers to inject arbitrary instructions. Untrusted pages can invoke the canvas bridge to execute malicious code within the Android application context.
Affected products
-
- Version 0StatusaffectedConstraints<2026.3.22
- Version 2026.3.22StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.3.22
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.3.22 |
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Apr 14, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
Apr–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.54% (0.00538) | 43.34th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.37% (0.00368) | 28.41th | v5 (v2026.06.15) |
| Apr 11, 2026 | 0.04% (0.00037) | 10.96th | v4 (v2025.03.14) |
References (6)
- https://github.com/advisories/GHSA-cxmw-p77q-wchg Advisory
- https://github.com/openclaw/openclaw/commit/630f1479c44f78484dfa21bb407cbe6f171dac87 patch
- https://github.com/openclaw/openclaw/commit/8b02ef133275be96d8aac2283100016c8a7f32e5 patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-cxmw-p77q-wchg vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-35643
- https://www.vulncheck.com/advisories/openclaw-arbitrary-code-execution-via-unvalidated-webview-javascriptinterface third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-cxmw-p77q-wchg | Advisory | |
| https://github.com/openclaw/openclaw/commit/630f1479c44f78484dfa21bb407cbe6f171dac87 | patch | |
| https://github.com/openclaw/openclaw/commit/8b02ef133275be96d8aac2283100016c8a7f32e5 | patch | |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-cxmw-p77q-wchg | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-35643 | ||
| https://www.vulncheck.com/advisories/openclaw-arbitrary-code-execution-via-unvalidated-webview-javascriptinterface | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.