OpenClaw Server-Side Request Forgery Vulnerability in Playwright Redirect Handling

Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in OpenClaw versions prior to 2026.4.8. This vulnerability resides in the Playwright redirect handling, where strict SSRF checks can be bypassed. Attackers may exploit this to access private targets that should be protected by browser SSRF safeguards.

Impact

Exploitation of this vulnerability allows for bypassing browser-imposed SSRF restrictions, potentially leading to unauthorized access to private resources.

Reproduction

The vulnerability can be reproduced by using OpenClaw version 2026.3.8 and navigating to a private target during a Playwright request-time navigation, which will bypass the standard SSRF protections.

Remediation

Users can upgrade to OpenClaw version 2026.4.8 or later to address this vulnerability.

Added: Apr 28, 2026, 8:13 PM
Updated: Apr 28, 2026, 8:13 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.4
exploitability
7.1
remediation
0.0
relevance
6.9
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.