Insecure Default Initialization of Resource in OpenClaw - #VU126442
Published: April 17, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to access internal services or metadata endpoints.
The vulnerability exists due to initialization of a resource with an insecure default in the browser SSRF policy when handling browser-driven requests to private-network destinations. A remote attacker can trigger browser-driven requests to private-network destinations to access internal services or metadata endpoints.
Private-network access was allowed by default in paths where restrictive behavior was expected.