Server-Side Request Forgery in OpenClaw Marketplace Plugin
CVE-2026-41302

4.8MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
20 April 2026

What is CVE-2026-41302?

OpenClaw versions prior to 2026.3.31 are susceptible to a server-side request forgery (SSRF) vulnerability in the marketplace plugin's download functionality. This vulnerability allows remote attackers to exploit unguarded fetch() calls, enabling them to perform arbitrary network requests. Such exploitation can lead to unauthorized access to internal resources or interaction with external services as if initiated by the compromised system.

Affected Version(s)

OpenClaw 0 < 2026.3.31

OpenClaw 2026.3.31

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tdjackey
.