CVE-2026-101883

CVE-2026-101883 published: OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability that bypasses URL risk evaluation enforced by canvas.navigate. Attackers with gateway or agent access can issue canvas.present to ma...

View full NVD advisory → ← Back to CVE watch