A vulnerability classified as critical has been found in mf-yang openclaw-cn up to 0.2.1. This affects the function
clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP API. Performing a manipulation results in server-side request forgery.
This vulnerability is cataloged as CVE-2026-17458. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.