Executive brief
OpenClaw's fetch-guard function handles HTTP requests and redirects, including those that cross to different domains. The vulnerability allowed sensitive authorization headers (such as API keys and private tokens) to be forwarded to unrelated domains during cross-origin redirects, exposing authentication credentials to attackers who control redirect targets. This could result in unauthorized API access or data theft using stolen credentials.
Technical details
OpenClaw's fetchWithSsrFGuard(...) function implemented a narrow denylist approach to filtering sensitive headers during cross-origin redirects, explicitly blocking only Authorization, Proxy-Authorization, Cookie, and Cookie2. Custom authorization headers such as X-Api-Key and Private-Token were not filtered, allowing them to be forwarded to different origins. An attacker controlling a redirect target can trigger cross-origin redirects and receive sensitive caller-supplied headers intended only for the original destination. The fix switches from a denylist to a safe-header allowlist, restricting survivors to benign headers like content negotiation and cache validators. The patch was released in version 2026.3.7 on March 8, 2026, addressing affected versions ≤ 2026.3.2.
Affected products
- OpenClaw openclaw <= 2026.3.2
Timeline
- 2026-03-09: disclosed
- 2026-03-08: patched: Version 2026.3.7 published