#VU125216 Server-Side Request Forgery (SSRF) in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to perform server-side request forgery.
The vulnerability exists due to server-side request forgery in multiple channel extensions when processing configured base URLs for outbound requests. A remote user can configure a crafted base URL to perform server-side request forgery.
The issue is an incomplete fix for a previous SSRF vulnerability.