PT-2026-26418 · Microsoft+1 · Ms Teams+1

Tdjackey

·

Published

2026-03-03

·

Updated

2026-03-20

·

CVE-2026-32037

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.22
Description OpenClaw versions before 2026.2.22 do not consistently validate redirect chains against configured mediaAllowHosts allowlists during MSTeams media downloads. Attackers can supply or influence attachment URLs to force redirects to non-allowlisted targets, bypassing Server-Side Request Forgery (SSRF) boundary controls. This occurs in specific attachment paths where redirect handling bypasses the configured mediaAllowHosts checks, and redirect chains are not consistently constrained to allowlisted targets before content is fetched.
Recommendations Versions prior to 2026.2.22 should be updated to version 2026.2.22 or later.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-32037
GHSA-W76H-8M22-HPGH

Affected Products

Ms Teams
Openclaw