Server-Side Request Forgery Vulnerability in OpenClaw by OpenClaw
CVE-2026-43576
4.9MEDIUM
What is CVE-2026-43576?
OpenClaw prior to version 2026.4.5 is vulnerable to a server-side request forgery (SSRF) that can be exploited through its CDP /json/version WebSocket endpoint. The lack of proper validation of the webSocketDebuggerUrl response enables attackers to manipulate the routing of connections to untrusted second-hop targets, posing significant security risks through potential redirection to arbitrary hosts. This vulnerability underscores the importance of input validation and secure coding practices.
Affected Version(s)
OpenClaw 0 < 2026.4.5
OpenClaw 2026.4.5
