PT-2026-29266 · Openclaw · Openclaw
Antaisecuritylab
·
Published
2026-03-31
·
Updated
2026-03-31
·
CVE-2026-34504
CVSS v3.1
8.3
High
| AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L |
OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers to fetch internal URLs. A malicious or compromised fal relay can exploit unguarded image download fetches to expose internal service metadata and responses through the image pipeline.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw