Executive brief
OpenClaw, a user-controlled local assistant, contains a vulnerability in how it handles web requests. When the software follows a link that redirects to a different website, it may incorrectly resend sensitive data or login headers to that new, potentially malicious destination. This could allow an attacker to steal private information or credentials by tricking the assistant into visiting a specially crafted link.
Technical details
A vulnerability in the `fetchWithSsrFGuard` function of OpenClaw allows for the replay of unsafe request bodies and sensitive headers across cross-origin redirects. The root cause is a failure to strip or validate the request body when following a redirect to a different origin, violating standard security practices for HTTP clients. An attacker can exploit this by triggering a redirect to a server they control, effectively exfiltrating the original request's data or authentication headers. This issue affects versions prior to 2026.4.8 and has been addressed in that release.
Affected products
- OpenClaw openclaw < 2026.4.8
Timeline
- 2026-04-08: advisory: Original advisory published by VulnCheck and NVD
- 2026-04-09: advisory: GitHub Advisory Database entry published
- 2026-04-10: patched: Fix verified and advisory updated