Server-Side Request Forgery (SSRF) in OpenClaw - CVE-2026-28476
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to induce the server to make HTTP requests to attacker-chosen hosts.
The vulnerability exists due to server-side request forgery (ssrf) in the Tlon (Urbit) extension authentication flow when constructing an outbound HTTP request from a user-provided base URL. A remote user can supply a crafted base URL to induce the server to make HTTP requests to attacker-chosen hosts.
Only deployments with the Tlon (Urbit) extension installed and configured are vulnerable, and exploitation requires the ability to influence the configured Urbit URL.