Back to overview

CVE-2026-17457

MEDIUM
4.3
CVSS 3.1
Description
A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserNavigationAllowed of the file src/browser/navigation-guard.ts of the component Scheme Handler. Such manipulation of the argument url leads to information disclosure. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Metadata

CVE ID
CVE-2026-17457
State
PUBLISHED
Assigner
VulDB
Reserved
2026-07-25 18:54 UTC
Published
2026-07-26 09:30 UTC
Last updated
2026-07-26 09:30 UTC
Primary CWE
CWE-200
Information Disclosure
Vendor / Product
mf-yang / openclaw-cn
Sources
cve.org  ·  NVD

Severity & Metrics

4.3 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R
Affected products (1)
VendorProductPlatformVersions
mf-yang openclaw-cn 0.2.0, 0.2.1
Weakness (CWE)
CWESourceDescription
CWE-200 cna Information Disclosure
CWE-284 cna Improper Access Controls
CVSS scores (4)
ScoreSeverityVersionSourceVector
5.3 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
4.3 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R
4.3 MEDIUM 3.0 cna CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R
4.0 N/D 2.0 cna AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR
References (6)
Back to overview