Executive brief
OpenClaw is a web search tool that generates citations for search results. A vulnerability in how it handles citation URL redirects allows an attacker to make the OpenClaw server itself issue requests to internal or private network addresses (like localhost or internal corporate servers). An attacker could use this to scan internal infrastructure, steal data from internal services, or disrupt internal operations.
Technical details
OpenClaw's web_search citation redirect resolution implements Server-Side Request Forgery (SSRF, CWE-918) via a private-network-allowing policy. The vulnerable component fails to restrict the destinations of citation URL redirects, allowing an attacker to influence citation targets that point to loopback addresses (127.0.0.1), private network ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), or other internal destinations. The attack requires only the ability to influence citation redirect targets and network-level access to the gateway; no authentication or user interaction is required. An attacker can trigger the OpenClaw host to fetch content from arbitrary internal-network destinations. The fix (version 2026.3.1 or later) replaces the permissive private-network-allowing SSRF policy with a strict/default policy that blocks localhost and private/internal redirect targets.
Affected products
- OpenClaw OpenClaw <= 2026.2.26
Timeline
- 2026-03-02: disclosed
- 2026-03-01: patched: Version 2026.3.1 or later