PT-2026-20952 · Openclaw · Openclaw

P80N-Sec

·

Published

2026-02-17

·

Updated

2026-03-22

·

CVE-2026-26322

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.14
Description The Gateway tool in OpenClaw accepted a tool-supplied gatewayUrl without sufficient restrictions, potentially causing the OpenClaw host to attempt outbound WebSocket connections to user-specified targets. This requires the ability to invoke tools that accept gatewayUrl overrides. The issue stemmed from tool call paths allowing gatewayUrl overrides to flow into the Gateway WebSocket client without validation, enabling connections to non-gateway endpoints like localhost services, private network addresses, or cloud metadata IPs. In most cases, this results in outbound connection attempts and errors. However, if the target speaks WebSocket and is reachable, further interaction may be possible.
Recommendations Versions prior to 2026.2.14 should be updated to version 2026.2.14 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-26322
GHSA-G6Q9-8FVW-F7RF

Affected Products

Openclaw