Executive brief
OpenClaw is a framework used by Microsoft Teams to handle media fetching and attachments. The vulnerability allows some requests to bypass security checks designed to prevent Server-Side Request Forgery (SSRF) attacks, where an attacker could potentially trick the system into fetching content from restricted internal networks or unauthorized hosts. This could expose internal resources or allow lateral movement within a corporate network.
Technical details
The vulnerability exists in OpenClaw's Microsoft Teams media handling code, which used inconsistent fetch paths for Graph metadata/content and attachment auth-retry flows. Some code paths relied on plugin-local fetch behavior instead of uniformly using shared SSRF-guarded fetch logic with pinned DNS and policy checks, creating inconsistent host/DNS enforcement across redirect and fetch hops. This is classified as a TOCTOU race condition (CWE-367) combined with SSRF (CWE-918). An authenticated user could potentially exploit this to bypass SSRF restrictions by using attachment download or media fetch endpoints. The fix unifies fetch behavior by routing all Graph message, hosted-content, and attachment fetches through centralized shared SSRF-guarded paths with consistent policy enforcement. A patch is available in version 2026.2.26.
Affected products
- OpenClaw openclaw <= 2026.2.25
Timeline
- 2026-03-03: disclosed: Advisory published
- 2026-02-26: patched: Fix commit 57334cd7d85174d5f951de01114fd5801b063564
- 2026-02-26: other: Patch version 2026.2.26 planned for release