Intel

AIKIDO-2026-57265

openclaw is vulnerable to Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF)CVE-2026-62201 Published 5 days ago

77

High Risk

This Affects:

JSopenclaw
0.0.1 - 2026.6.5
Fixed in 2026.6.6
Are you affected? Scan for Free

TL;DR

The sandbox exec-server forwards HTTP requests without enforcing OpenClaw network policy against destinations that should be blocked. A lower-trust caller that can reach this path can use it to access internal network resources that policy was meant to deny. The fix applies network policy checks to exec-server requests before they are sent.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and the sandbox exec-server is enabled and reachable by lower-trust callers.

Background info

openclaw is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.1 - 2026.6.5.

How to fix this

Upgrade the openclaw library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform