CVE-2026-41912
OpenClaw before 2026.4.8 contains a server-side request forgery policy bypass vulnerability allowing attackers to trigger navigations bypassing normal SSRF checks. Attackers can exploit browser interactions to bypass SSRF protections and access restricted resources.
View on NVDAnalysis
OpenClaw is an open-source game engine project for a 1997 platformer, which is not relevant to professional web, mobile, or backend development. While the SSRF vulnerability is rated as high severity, the product is niche software and does not affect the common open-source stack used by the community.
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:NCWE-918EPSS
Affects
openclaw:openclawTechnical description
OpenClaw before 2026.4.8 contains a server-side request forgery policy bypass vulnerability allowing attackers to trigger navigations bypassing normal SSRF checks. Attackers can exploit browser interactions to bypass SSRF protections and access restricted resources.