Skip to content
CVSS 7.6 · HIGH

CVE-2026-41912

OpenClaw before 2026.4.8 contains a server-side request forgery policy bypass vulnerability allowing attackers to trigger navigations bypassing normal SSRF checks. Attackers can exploit browser interactions to bypass SSRF protections and access restricted resources.

View on NVD

Analysis

OpenClaw is an open-source game engine project for a 1997 platformer, which is not relevant to professional web, mobile, or backend development. While the SSRF vulnerability is rated as high severity, the product is niche software and does not affect the common open-source stack used by the community.

Severity

Score: 7.6(HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
AV: NETWORK
AC: LOW
PR: LOW
UI: REQUIRED
S: CHANGED
C: HIGH
I: LOW
A: NONE
Weakness (CWE): CWE-918

EPSS

Probability of exploitation (next 30 days): 0.0003 (0.0%)
Percentile: 8.1%
EPSS: 2026-05-06

Affects

openclaw:openclaw

Technical description

OpenClaw before 2026.4.8 contains a server-side request forgery policy bypass vulnerability allowing attackers to trigger navigations bypassing normal SSRF checks. Attackers can exploit browser interactions to bypass SSRF protections and access restricted resources.

Published: 4/28/2026, 7:37:44 PM
Last modified: 4/30/2026, 7:38:47 PM

References

HomeEventsBlogResourcesTeam