OpenClaw Server-Side Request Forgery Vulnerability in Citation Redirect Resolution

Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in OpenClaw versions prior to 2026.3.1. This vulnerability resides in the 'web_search' citation redirect resolution, where a lenient SSRF policy allows attackers to target private-network destinations. By influencing citation redirect targets, attackers can initiate internal-network requests from the OpenClaw gateway host.

Impact

Exploitation of this vulnerability could allow an attacker to send requests to internal network resources from the OpenClaw gateway host, potentially leading to unauthorized access or manipulation of internal services or data.

Remediation

Users can upgrade to OpenClaw version 2026.3.1 or later to address this vulnerability. The patched version implements a stricter SSRF policy that blocks redirects to localhost, private, or internal network targets.

Added: Mar 23, 2026, 10:29 PM
Updated: Mar 23, 2026, 10:29 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.8
remediation
0.0
relevance
4.6
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.