PT-2026-33864 · Openclaw · Openclaw

Antaisecuritylab

·

Published

2026-04-07

·

Updated

2026-04-21

·

CVE-2026-41297

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.31
Description A server-side request forgery (SSRF) issue exists in the marketplace plugin download functionality. The marketplace.ts module fails to restrict redirect destinations during archive downloads, allowing remote attackers to access internal resources or redirect requests to arbitrary internal or external servers by following unvalidated redirects.
Recommendations Update to version 2026.3.31 or later. As a temporary workaround, restrict access to the marketplace.ts module to minimize the risk of exploitation.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41297
GHSA-VJX8-8P7H-82GR

Affected Products

Openclaw