SSRF Guard Bypass in OpenClaw by OpenClaw Team
CVE-2026-41361
5.1MEDIUM
What is CVE-2026-41361?
OpenClaw versions prior to 2026.3.28 are vulnerable to a security issue where the SSRF guard is unable to effectively block certain IPv6 special-use ranges. This can allow attackers to exploit the vulnerability by crafting specific URLs that target internal or non-routable IPv6 addresses, thereby bypassing SSRF protections. As a result, systems using affected versions of OpenClaw may be at risk of unauthorized internal data access.
Affected Version(s)
OpenClaw 0 < 2026.3.28
OpenClaw 2026.3.28
