Openclaw · Openclaw · CVE-2026-41912
**Name of the Vulnerable Software and Affected Versions**
OpenClaw versions prior to 2026.4.8
**Description**
A server-side request forgery (SSRF) policy bypass allows attackers to trigger navigations that circumvent standard SSRF checks. By exploiting browser interactions, attackers can bypass these protections to access restricted resources. SSRF is a flaw where an attacker can force a server-side application to make HTTP requests to an arbitrary domain of the attacker's choosing.
**Recommendations**
Update to version 2026.4.8.