CVE-2026-28467

OpenClaw versions prior to 2026.2.2 contain a server-side request forgery vulnerability in attachment and media URL hydration that allows remote attackers to fetch arbitrary HTTP(S) URLs. Attackers who can influence media URLs through model-controlled sendAttachment or auto-reply mechanisms can trigger SSRF to internal resources and exfiltrate fetched response bytes as outbound attachments.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

09 Mar 2026, 15:28

Type Values Removed Values Added
References () https://github.com/openclaw/openclaw/commit/81c68f582d4a9a20d9cca9f367d2da9edc5a65ae - () https://github.com/openclaw/openclaw/commit/81c68f582d4a9a20d9cca9f367d2da9edc5a65ae - Patch
References () https://github.com/openclaw/openclaw/commit/9bd64c8a1f91dda602afc1d5246a2ff2be164647 - () https://github.com/openclaw/openclaw/commit/9bd64c8a1f91dda602afc1d5246a2ff2be164647 - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-wfp2-v9c7-fh79 - () https://github.com/openclaw/openclaw/security/advisories/GHSA-wfp2-v9c7-fh79 - Exploit, Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-ssrf-via-attachment-media-url-hydration - () https://www.vulncheck.com/advisories/openclaw-ssrf-via-attachment-media-url-hydration - Third Party Advisory
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
First Time Openclaw openclaw
Openclaw

09 Mar 2026, 13:36

Type Values Removed Values Added
Summary
  • (es) Las versiones de OpenClaw anteriores a la 2026.2.2 contienen una vulnerabilidad de falsificación de petición del lado del servidor en la hidratación de URL de adjuntos y medios que permite a atacantes remotos obtener URL HTTP(S) arbitrarias. Los atacantes que pueden influir en las URL de medios a través de mecanismos de sendAttachment o de respuesta automática controlados por el modelo pueden desencadenar SSRF a recursos internos y exfiltrar los bytes de respuesta obtenidos como adjuntos salientes.

06 Mar 2026, 17:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.3
v2 : unknown
v3 : 6.5

05 Mar 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-05 22:16

Updated : 2026-03-09 15:28


NVD link : CVE-2026-28467

Mitre link : CVE-2026-28467

CVE.ORG link : CVE-2026-28467


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-918

Server-Side Request Forgery (SSRF)