Junglewise Threat Intelligence

CVE-2026-53859: OpenClaw hostname validation bypass in model and workspace URLs

CVE-2026-53859 · Severity: medium · CVSS 6.5 · Published 2026-06-16

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a tool used for managing workspace and model-derived URLs, contains a flaw in how it validates web addresses. An attacker could bypass security filters by adding a trailing dot to a restricted web address, potentially allowing them to access internal or private network resources that should be blocked. This could lead to the exposure of sensitive internal data or metadata.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in OpenClaw due to improper input validation of hostnames. The application's hostname blocklist check fails to account for trailing dots (e.g., 'example.com.'), treating them differently than the standard hostname ('example.com'). An authenticated attacker with low privileges can provide a crafted URL containing a trailing dot to bypass security policies and reach restricted internal network destinations or metadata services. The issue is fixed in version 2026.5.26.

Affected products

  • openclaw openclaw <= 2026.5.22

Timeline

  • 2026-05-28: disclosed
  • 2026-05-28: advisory: Initial GitHub advisory published
  • 2026-06-18: patched: First stable patched version 2026.5.26 confirmed

References

Related threats