Executive brief
OpenClaw is a network utility that includes security controls to prevent Server-Side Request Forgery (SSRF) attacks, which are used to make the application access internal or non-routable network addresses. The SSRF guard failed to block four specific IPv6 address ranges that should have been restricted, allowing an attacker controlling a fetched URL to bypass these protections and target internal infrastructure.
Technical details
The vulnerability is a Server-Side Request Forgery (SSRF) bypass in the IP classifier component (src/shared/net/ip.ts, src/infra/net/ssrf.*). The SSRF guard incorrectly treated four IPv6 special-use ranges as public addresses and allowed HTTP requests to proceed to those ranges instead of blocking them. An attacker with control over a URL parameter passed to OpenClaw could exploit this to fetch internal or non-routable IPv6 addresses that should have been filtered by the SSRF protection. The vulnerability requires low privilege (authenticated user) and has high attack complexity. The fix is available in version 2026.3.28 and later, with the patch committed as d61f8e5672.
Affected products
- OpenClaw OpenClaw <= 2026.3.24
Timeline
- 2026-03-31: disclosed
- 2026-03-28: patched: Version 2026.3.28 contains the fix