PT-2026-49776 · Openclaw · Openclaw

·

CVE-2026-53859

·

Published

2026-06-16

·

Updated

2026-06-18

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.5.26
Description An issue exists in hostname validation where trailing-dot notation in model or workspace-derived URLs can be used to bypass blocklist comparisons. This occurs because hostname checks treat hosts with a trailing dot inconsistently, allowing requests to reach destinations that operators intended to block through hostname policies.
Recommendations Update to version 2026.5.26. Keep private-network and metadata destinations blocked at the proxy or network layer. Maintain narrow channel and tool allowlists. Avoid sharing one Gateway between mutually untrusted users. Disable the affected feature when it is not needed.

Exploit

Fix

RCE

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53859
GHSA-GXG4-2RRR-JHC7
GHSA-VQX6-6J84-2794

Affected Products

Openclaw