Junglewise Threat Intelligence

CVE-2026-28476: OpenClaw affected by SSRF in optional Tlon (Urbit) extension authentication

CVE-2026-28476 · Severity: high · CVSS 8.3 · Published 2026-02-18

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a web application that supports optional authentication plugins, including one for Tlon (Urbit). The Tlon authentication extension accepts a user-provided Urbit server URL and uses it to make outbound HTTP requests without proper validation, allowing attackers to redirect those requests to internal or arbitrary systems. In deployments where untrusted users can configure this URL setting, an attacker could gain information about or access to internal services that would normally be isolated from the network.

Technical details

The vulnerability is a server-side request forgery (CWE-918) in the optional Tlon (Urbit) authentication extension. The root cause is insufficient validation of a user-provided base URL before constructing and executing an outbound HTTP request. An attacker who can influence the configured Urbit URL (typically a configuration setting) can redirect the gateway's outbound requests to attacker-controlled or internal hosts, including private network addresses. The vulnerability requires the Tlon extension to be installed and configured, and the attacker must have the ability to modify the Urbit URL setting. The fix, released in version 2026.2.14, adds URL validation and normalization, and implements an SSRF guard that blocks private/internal hosts by default, with an opt-in override flag available.

Affected products

  • OpenClaw OpenClaw <=2026.2.13

Timeline

  • 2026-02-18: disclosed
  • 2026-02-14: patched: Fixed in version 2026.2.14

References

Related threats