PT-2026-99213 · Openclaw · Openclaw
CVE-2026-100577
·
Published
2026-09-26
·
Updated
2026-09-30
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.8.1
Description
OpenClaw fails to validate video asset URLs returned by providers, which enables server-side requests to private destinations. A malicious or compromised provider can return private or loopback URLs, causing the CLI to make requests to internal services accessible from the OpenClaw host.
Recommendations
Update to version 2026.8.1.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw