PT-2026-99213 · Openclaw · Openclaw

CVE-2026-100577

·

Published

2026-09-26

·

Updated

2026-09-30

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.8.1
Description OpenClaw fails to validate video asset URLs returned by providers, which enables server-side requests to private destinations. A malicious or compromised provider can return private or loopback URLs, causing the CLI to make requests to internal services accessible from the OpenClaw host.
Recommendations Update to version 2026.8.1.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100577
GHSA-FVXR-9G24-X3HF

Affected Products

Openclaw