Executive brief
OpenClaw, a platform for managing AI models and workspaces, contains a security flaw in how it validates web addresses. An attacker can bypass security filters by adding a trailing dot to a hostname, potentially allowing them to access internal or restricted network resources that should be blocked. This could lead to the exposure of sensitive internal data or unauthorized access to private services.
Technical details
OpenClaw before version 2026.5.26 is vulnerable to Server-Side Request Forgery (SSRF) due to improper input validation (CWE-20, CWE-918). The vulnerability arises from an incomplete comparison (CWE-1023) where hostname blocklists fail to account for trailing-dot notation (e.g., 'example.com.'). An authenticated attacker with low privileges can provide a specially crafted URL in model or workspace-derived paths to bypass security policies and reach restricted destinations. This allows for unauthorized access to internal network metadata or private services. The issue is resolved in version 2026.5.26.
Affected products
- OpenClaw openclaw < 2026.5.26
Timeline
- 2026-05-28: advisory: Original GHSA-gxg4-2rrr-jhc7 published
- 2026-06-16: disclosed: CVE-2026-53859 published
- 2026-06-18: other: Duplicate advisory GHSA-vqx6-6j84-2794 withdrawn