Server-Side Request Forgery (SSRF) in OpenClaw - #VU132693
Published: May 29, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to perform server-side request forgery.
The vulnerability exists due to improper input validation in hostname policy checks for model- or workspace-derived URLs when handling a hostname presented with a trailing dot. A remote user can supply a URL using a trailing-dot hostname to perform server-side request forgery.
Exploitation requires the affected feature to be enabled and reachable, and practical impact depends on whether lower-trust input can reach the affected request path.