Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. openclaw
  4. ›
  5. GHSA-25gx-x37c-7pph

GHSA-25gx-x37c-7pph: OpenClaw's andbox browser noVNC observer lacked VNC authentication

March 3, 2026

The sandbox browser entrypoint launched x11vnc without authentication (-nopw) for noVNC observer sessions.

OpenClaw-managed runtime flow publishes the noVNC port to host loopback only (127.0.0.1), so default exposure is local to the host unless operators explicitly expose the port more broadly (or run the image standalone with broad port publishing).

References

  • github.com/advisories/GHSA-25gx-x37c-7pph
  • github.com/openclaw/openclaw
  • github.com/openclaw/openclaw/commit/621d8e1312482f122f18c43c72c67211b141da01
  • github.com/openclaw/openclaw/commit/8c1518f0f3e0533593cd2dec3a46c9b746753661
  • github.com/openclaw/openclaw/security/advisories/GHSA-25gx-x37c-7pph

Code Behaviors & Features

Detect and mitigate GHSA-25gx-x37c-7pph with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2026.2.21

Fixed versions

  • 2026.2.21

Solution

Upgrade to version 2026.2.21 or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-287: Improper Authentication
  • CWE-862: Missing Authorization

Source file

npm/openclaw/GHSA-25gx-x37c-7pph.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 24 Mar 2026 12:17:17 +0000.