CVE-2026-41398: OpenClaw: iOS A2UI bridge trusted generic local-network pages for agent.request dispatch
(updated )
Before OpenClaw 2026.4.2, the iOS A2UI bridge treated generic local-network pages as trusted bridge origins. A page loaded from a local-network or tailnet host could trigger agent.request dispatch without the stricter trusted-canvas origin check.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-41398 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →