Server-Side Request Forgery in OpenClaw by OpenClaw
CVE-2026-100577
5.3MEDIUM
What is CVE-2026-100577?
OpenClaw has a vulnerability in versions prior to 2026.8.1 that does not adequately validate video asset URLs received from providers. This failure allows for the exploitation of the server-side request forgery (SSRF) vulnerability, where a malicious or compromised provider can send private or loopback URLs. Consequently, this can lead the command-line interface (CLI) to make requests to internal services of the OpenClaw host, potentially exposing sensitive information or causing unintended actions.
Affected Version(s)
OpenClaw 0 < 2026.8.1
OpenClaw 2026.8.1
