GHSA-qw99-grcx-4pvm: OpenClaw's Chrome extension relay binds publicly due to wildcard treated as loopback
The Chrome extension relay (ensureChromeExtensionRelayServer) previously treated wildcard hosts (0.0.0.0 / ::) as loopback, which could make it bind the relay HTTP/WS server to all interfaces when a wildcard cdpUrl was passed.
References
Code Behaviors & Features
Detect and mitigate GHSA-qw99-grcx-4pvm with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →