OpenClaw versions prior to 2026.2.14 contain a server-side request forgery vulnerability in the optional Tlon Urbit extension that accepts user-provided base URLs for authentication without proper validation. Attackers who can influence the configured Urbit URL can induce the gateway to make HTTP requests to arbitrary hosts including internal addresses.
References
Configurations
History
21 Apr 2026, 14:52
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/openclaw/openclaw/commit/bfa7d21e997baa8e3437657d59b1e296815cc1b1 - Patch | |
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-pg2v-8xwh-qhcc - Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-server-side-request-forgery-in-tlon-extension-authentication - Third Party Advisory | |
| First Time |
Openclaw openclaw
Openclaw |
|
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
09 Mar 2026, 13:36
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
06 Mar 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.3 |
05 Mar 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-05 22:16
Updated : 2026-04-21 14:52
NVD link : CVE-2026-28476
Mitre link : CVE-2026-28476
CVE.ORG link : CVE-2026-28476
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-918
Server-Side Request Forgery (SSRF)
