Server-Side Request Forgery in OpenClaw Marketplace Plugin
CVE-2026-41302
4.8MEDIUM
What is CVE-2026-41302?
OpenClaw versions prior to 2026.3.31 are susceptible to a server-side request forgery (SSRF) vulnerability in the marketplace plugin's download functionality. This vulnerability allows remote attackers to exploit unguarded fetch() calls, enabling them to perform arbitrary network requests. Such exploitation can lead to unauthorized access to internal resources or interaction with external services as if initiated by the compromised system.
Affected Version(s)
OpenClaw 0 < 2026.3.31
OpenClaw 2026.3.31
