Executive brief
OpenClaw, an AI-related integration platform, contains a flaw in how it handles message forwarding. An attacker can manipulate the system to send sensitive Gateway access tokens and data payloads to a location they control. This could lead to the theft of credentials, allowing an unauthorized user to perform actions on the platform as if they were a legitimate administrator or service.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in OpenClaw's message.action forwarding mechanism. The root cause is insufficient validation of model-controlled metadata, which allows an attacker to specify a malicious loopback URL as a Gateway target. When the action is processed, the system forwards the action payload along with sensitive Gateway credentials (tokens) to the attacker-controlled listener. This requires the attacker to have low-level authenticated access to provide input that reaches the model-controlled metadata path. The vulnerability is patched in version 2026.5.2.
Affected products
- OpenClaw OpenClaw < 2026.5.2
Timeline
- 2026-05-28: advisory: GitHub Security Advisory published
- 2026-06-12: disclosed: NVD publication date