Server-Side Request Forgery (SSRF) in OpenClaw - #VU135911
Published: June 30, 2026
Vulnerability details
The vulnerability allows a remote user to access network destinations that should have been blocked by OpenClaw policy.
The vulnerability exists due to server-side request forgery (SSRF) in browser snapshot routes when processing post-navigation requests. A remote user can supply a crafted input path to access network destinations that should have been blocked by OpenClaw policy.
Only instances with the affected feature enabled and reachable are vulnerable, and practical impact depends on whether lower-trust input can reach that path.