Server-Side Request Forgery (SSRF) in OpenClaw - CVE-2026-28476

 

Server-Side Request Forgery (SSRF) in OpenClaw - CVE-2026-28476

Published: May 4, 2026


Vulnerability identifier: #VU129476
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-28476
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to induce the server to make HTTP requests to attacker-chosen hosts.

The vulnerability exists due to server-side request forgery (ssrf) in the Tlon (Urbit) extension authentication flow when constructing an outbound HTTP request from a user-provided base URL. A remote user can supply a crafted base URL to induce the server to make HTTP requests to attacker-chosen hosts.

Only deployments with the Tlon (Urbit) extension installed and configured are vulnerable, and exploitation requires the ability to influence the configured Urbit URL.


Affected software

OpenClaw

How to mitigate CVE-2026-28476

Install security update from vendor's website.

OpenClaw - update to 2026.2.14

External References

Related Security Bulletins