OpenClaw Server-Side Request Forgery Vulnerability in Citation Redirect Resolution
Vulnerability
A server-side request forgery (SSRF) vulnerability has been identified in OpenClaw versions prior to 2026.3.1. This vulnerability resides in the 'web_search' citation redirect resolution, where a lenient SSRF policy allows attackers to target private-network destinations. By influencing citation redirect targets, attackers can initiate internal-network requests from the OpenClaw gateway host.
Impact
Exploitation of this vulnerability could allow an attacker to send requests to internal network resources from the OpenClaw gateway host, potentially leading to unauthorized access or manipulation of internal services or data.
Remediation
Users can upgrade to OpenClaw version 2026.3.1 or later to address this vulnerability. The patched version implements a stricter SSRF policy that blocks redirects to localhost, private, or internal network targets.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
