Executive brief
OpenClaw is a local AI assistant application that uses the Playwright browser automation library to handle web requests. An attacker can bypass the application's server-side request forgery (SSRF) protections by exploiting how Playwright handles HTTP redirects, allowing them to reach private network resources that should be blocked. This could expose internal services and data not intended for external access.
Technical details
The vulnerability is a server-side request forgery (CWE-918) bypass in OpenClaw's Playwright integration. Strict SSRF checks are intended to prevent requests to private targets, but the application fails to validate the final destination when Playwright performs request-time redirects—allowing an attacker-controlled redirect chain to reach blocked private IP ranges or hostnames. The attack requires user interaction to trigger a malicious request through the OpenClaw interface (requires login/access to the local assistant). An attacker can enumerate and access internal services that should be unreachable. The vulnerability was patched in version 2026.4.8; affected versions are 2026.3.8 and earlier, with fix verified in commit d7c3210cd6f5fdfdc1beff4c9541673e814354d5.
Affected products
- OpenClaw OpenClaw 2026.3.8 and earlier; patched in 2026.4.8
Timeline
- 2026-04-09: disclosed: Published on GitHub Advisory Database
- 2026-04-08: patched: Fix available in version 2026.4.8