CVE-2026-32008 is a medium-severity improper URL scheme validation vulnerability (CWE-610) affecting OpenClaw versions prior to 2026.2.21. This flaw allows authenticated users with browser-tool access to navigate to file:// URLs. Attackers can exploit this to exfiltrate sensitive local files readable by the OpenClaw process user through browser snapshot and extraction actions, resulting in a high confidentiality impact. Rated with a CVSS score of 6.5, it requires low privileges and has low attack complexity, but no user interaction is needed. There is currently no evidence of active exploitation, nor are public exploit modules or significant community discussion available for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2026.2.21CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
< 2026.2.21CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.