Junglewise Threat Intelligence

CVE-2026-34504: OpenClaw SSRF in fal image-generation-provider.ts

CVE-2026-34504 · Severity: high · CVSS 8.3 · Published 2026-03-31

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, an open-source platform, contains a security flaw in how it handles image generation requests. An attacker or a compromised service provider could trick the system into making unauthorized requests to internal company servers. This could lead to the exposure of sensitive internal data, service metadata, or private system responses that are not intended to be accessible from the outside.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the OpenClaw 'fal' provider within the 'image-generation-provider.ts' component. The root cause is the use of raw, unguarded fetch operations for both API traffic and image download URLs, bypassing existing SSRF protections. A malicious or compromised fal relay can provide crafted URLs that force the OpenClaw server to fetch resources from internal services. This can result in the exposure of internal service metadata and responses through the image processing pipeline. The issue is fixed in version 2026.3.28 by implementing guarded fetch paths.

Affected products

  • OpenClaw OpenClaw < 2026.3.28

Timeline

  • 2026-03-27: patched: Fix committed to repository
  • 2026-03-29: advisory: GitHub Security Advisory published
  • 2026-03-31: disclosed: CVE published and NVD entry created

References

Related threats