Executive brief
OpenClaw is a Node.js library used to manage file attachments and media in applications. Vulnerable versions allow attackers to trigger server-side request forgery (SSRF) by influencing attachment URLs, enabling the gateway to fetch and exfiltrate data from internal-only services (such as metadata endpoints, private IP addresses, or localhost services) that would normally be inaccessible to the attacker. This is a data-leak risk that can expose sensitive internal information.
Technical details
OpenClaw versions prior to 2026.2.2 perform remote media fetching using raw fetch(url) calls without SSRF protections (CWE-918). An attacker who can influence attachment or media URLs (through model-controlled sendAttachment or auto-reply configurations) can provide URLs targeting internal endpoints like 127.0.0.1, RFC1918 private ranges, or cloud metadata services. The vulnerable gateway then fetches these URLs and returns the response bytes as an attachment payload, allowing the attacker to exfiltrate internal data. No authentication or user interaction is required. The fix, released in version 2026.2.2, implements SSRF protections including private/loopback/link-local blocking, DNS pinning, and redirect handling.
Affected products
- OpenClaw openclaw < 2026.2.2
Timeline
- 2026-02-05: disclosed: Advisory created
- 2026-02-04: patched: Fixed in version 2026.2.2
- 2026-02-17: advisory: Published as GHSA-wfp2-v9c7-fh79 and CVE-2026-28467