Open redirect in OpenClaw - CVE-2026-40037
Published: April 30, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to cause sensitive request bodies or headers to be sent to an unintended cross-origin destination.
The vulnerability exists due to improper handling of cross-origin redirects in fetchWithSsrFGuard when following cross-origin redirects. A remote attacker can trigger a redirect chain that replays an unsafe request body or headers to cause sensitive request bodies or headers to be sent to an unintended cross-origin destination.