A vulnerability described as problematic has been identified in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function
assertBrowserNavigationAllowed of the file src/browser/navigation-guard.ts of the component Scheme Handler. Such manipulation of the argument url leads to information disclosure.
This vulnerability is listed as CVE-2026-17457. The attack may be performed from remote. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.