PT-2026-35794 · Openclaw · Openclaw

Ccreater

+2

·

Published

2026-04-09

·

Updated

2026-04-30

·

CVE-2026-41912

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.4.8
Description A server-side request forgery (SSRF) policy bypass allows attackers to trigger navigations that circumvent standard SSRF checks. By exploiting browser interactions, attackers can bypass these protections to access restricted resources. SSRF is a flaw where an attacker can force a server-side application to make HTTP requests to an arbitrary domain of the attacker's choosing.
Recommendations Update to version 2026.4.8.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41912
GHSA-VR5G-MMX7-H897

Affected Products

Openclaw