Server-Side Request Forgery (SSRF) in OpenClaw - #VU129399
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to perform server-side request forgery against internal or private network targets.
The vulnerability exists due to insufficient destination validation in the SSRF hostname/IP guard when processing crafted URLs containing an ISATAP IPv6 literal with an embedded IPv4 address. A remote attacker can supply a specially crafted URL to perform server-side request forgery against internal or private network targets.
Exploitation requires reaching a URL-fetching path with attacker-controlled input.