Junglewise Threat Intelligence

CVE-2026-100601: ClawHub server-side request forgery in profile image preview

CVE-2026-100601 · Severity: medium · CVSS 5.3 · Published 2026-09-26

Technologies: Openclaw ClawHub. Vendors: Openclaw.

Executive brief

ClawHub is a collaborative development platform used to manage code projects and profiles. The public profile preview feature fetches user-provided image URLs but does not properly validate that the resolved destination is actually a public address, allowing attackers to direct it toward internal systems through DNS rebinding attacks. While a proof-of-concept only demonstrated outbound connections to attacker-controlled addresses, this could enable access to internal services or credential theft.

Technical details

ClawHub's profile preview image fetching validates the textual hostname against private-address patterns (CWE-918) but fails to pin the resolved network destination, enabling DNS rebinding attacks where a public-looking hostname resolves to an internal address or changes between validation and connection. Network-accessible; no authentication or user interaction required for exploitation beyond providing a crafted URL. A maintainer-controlled local harness confirmed outbound connections to private addresses; production impact assessment did not test access to internal services or credentials.

Affected products

  • OpenClaw ClawHub before revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650

Timeline

  • 2026-09-11: disclosed
  • 2026-09-11: patched: Deployed to clawhub.ai in revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650; self-hosted deployments should update to this revision or later

References

Related threats