Junglewise Threat Intelligence

CVE-2026-6011: OpenClaw SSRF in web-fetch tool

CVE-2026-6011 · Severity: medium · CVSS 5.6 · Published 2026-04-10

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is an AI agent platform that automates tasks across various systems. The web-fetch tool used by agents to retrieve remote content contains a server-side request forgery vulnerability that could allow an attacker to make the application access internal services or private network resources that should not be directly reachable. While the attack has high complexity and requires specific conditions, successful exploitation could expose sensitive internal data or facilitate further compromise of the hosting environment.

Technical details

The vulnerability is a server-side request forgery (CWE-918) in src/agents/tools/web-fetch.ts, specifically in the assertPublicHostname handler which is responsible for validating that fetched URLs point to public hosts. The handler fails to properly validate hostnames, allowing an attacker to craft URLs that bypass validation through DNS rebinding or similar techniques. The attack is network-reachable and requires no authentication or user interaction, though it is noted as having high complexity. Successful exploitation allows an attacker to make the OpenClaw instance fetch URLs from restricted internal networks or localhost services. The fix in version 2026.1.29 (commit b623557a2ec7e271bda003eb3ac33fbb2e218505) hardens URL fetching with DNS pinning to prevent rebinding attacks.

Affected products

  • OpenClaw OpenClaw up to 2026.1.26

Timeline

  • 2026-04-10: disclosed: GHSA-52vj-fvrv-7q82 published
  • 2026-01-26: patched: Fix committed and released in version 2026.1.29

References

Related threats