Executive brief
OpenClaw is a popular open-source automation and workflow platform that uses cron-based webhooks to trigger actions on external systems. A vulnerability in webhook delivery allowed attackers to bypass security checks and reach private, internal, or cloud metadata endpoints—potentially exposing sensitive configuration data or credentials without proper access controls.
Technical details
The vulnerability is a Server-Side Request Forgery (SSRF) in the cron webhook delivery mechanism (src/gateway/server-cron.ts). The code used fetch() directly to deliver webhooks without implementing SSRF policy checks, allowing an attacker to craft webhook URLs targeting internal/private endpoints (e.g., 169.254.169.254, localhost services, internal IPs). The attack requires the attacker to control or influence webhook target configuration, but no additional authentication or user interaction is needed. An attacker can probe internal services, retrieve cloud metadata, or access administrative interfaces. The vulnerability was patched in version 2026.2.18 and later.
Affected products
- OpenClaw openclaw <= 2026.2.17
Timeline
- 2026-02-20: disclosed: GHSA-w45g-5746-x9fp published
- 2026-02-18: patched: Fix released in version 2026.2.18