Server-Side Request Forgery in OpenClaw npm Package by OpenClaw
CVE-2026-100574

8.2HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100574?

The OpenClaw npm package before version 2026.8.1 contains a server-side request forgery (SSRF) flaw associated with its trusted-host DNS checks. This vulnerability allows requests to bypass destination validation if a trusted hostname resolves to an unspecified address (such as 0.0.0.0). As a result, an attacker with control over DNS for an allowed hostname can manipulate requests, potentially redirecting them to services that are only accessible via loopback interfaces. This poses risks depending on the data returned by those services, necessitating prompt updates to the latest version to mitigate this issue.

Affected Version(s)

OpenClaw 0 < 2026.8.1

OpenClaw 2026.8.1

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

qc9c
.