What is CVE-2026-17457?
An information disclosure vulnerability was found in mf-yang openclaw-cn versions up to 0.2.1, impacting the `Scheme Handler` component. The issue in the `assertBrowserNavigationAllowed` function within `src/browser/navigation-guard.ts` allows manipulation of the URL argument to leak sensitive data. Users should update the platform to mitigate the risk.
Azərbaycanca: mf-yang openclaw-cn platformasının 0.2.1-ə qədər versiyalarında `Scheme Handler` komponentində məlumat sızması zəifliyi aşkar edilib. `assertBrowserNavigationAllowed` funksiyası vasitəsilə URL arqumentinin manipulyasiyası məxfiliyin pozulmasına səbəb ola bilər. İstifadəçilərə platformanı yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which component of the openclaw-cn platform is affected by CVE-2026-17457?
CVE-2026-17457 affects the Scheme Handler component of the openclaw-cn platform.
What should be done to mitigate the vulnerability CVE-2026-17457?
To mitigate CVE-2026-17457, it is recommended to update the openclaw-cn platform.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.