Server-Side Request Forgery (SSRF) in OpenClaw - CVE-2026-32037
Published: May 1, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to perform server-side request forgery.
The vulnerability exists due to insufficient destination validation in MSTeams media download flows when processing attachment URLs that trigger redirect chains. A remote attacker can supply or influence an attachment URL to perform server-side request forgery.
The issue affects specific attachment paths where redirects were not consistently constrained to allowlisted targets before fetched content was accepted.