OpenClaw Server-Side Request Forgery Vulnerability in Playwright Redirect Handling
Vulnerability
A server-side request forgery (SSRF) vulnerability has been identified in OpenClaw versions prior to 2026.4.8. This vulnerability resides in the Playwright redirect handling, where strict SSRF checks can be bypassed. Attackers may exploit this to access private targets that should be protected by browser SSRF safeguards.
Impact
Exploitation of this vulnerability allows for bypassing browser-imposed SSRF restrictions, potentially leading to unauthorized access to private resources.
Reproduction
The vulnerability can be reproduced by using OpenClaw version 2026.3.8 and navigating to a private target during a Playwright request-time navigation, which will bypass the standard SSRF protections.
Remediation
Users can upgrade to OpenClaw version 2026.4.8 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
