Server-Side Request Forgery (SSRF) in OpenClaw - #VU128594
Published: April 30, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to probe private-network or metadata endpoints.
The vulnerability exists due to server-side request forgery (SSRF) in browser CDP profile creation and profile status flows when processing a stored cdpUrl value. A remote user can create a profile with a crafted CDP endpoint to probe private-network or metadata endpoints.
Only deployments that explicitly disabled private-network CDP targets in strict mode are affected.