PT-2026-49776 · Openclaw · Openclaw
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.5.26
Description
An issue exists in hostname validation where trailing-dot notation in model or workspace-derived URLs can be used to bypass blocklist comparisons. This occurs because hostname checks treat hosts with a trailing dot inconsistently, allowing requests to reach destinations that operators intended to block through hostname policies.
Recommendations
Update to version 2026.5.26.
Keep private-network and metadata destinations blocked at the proxy or network layer.
Maintain narrow channel and tool allowlists.
Avoid sharing one Gateway between mutually untrusted users.
Disable the affected feature when it is not needed.
Exploit
Fix
RCE
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw