


Perceptive Security
SOC/SIEM Consultancy

OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functionality that allows remote attackers to …
Published:
20 april 2026 om 22:00:00
Alert date:
21 april 2026 om 07:08:02
Source:
nvd.nist.gov
Web Technologies
OpenClaw versions prior to 2026.3.31 contain a server-side request forgery (SSRF) vulnerability in the marketplace plugin download functionality. The vulnerability stems from unguarded fetch() calls that allow remote attackers to make arbitrary network requests. Attackers can exploit this flaw to access internal resources or interact with external services on behalf of the affected system. The vulnerability is present in the marketplace plugin download feature and poses a high security risk.
Technical details
Mitigation steps:
Affected products:
OpenClaw
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-41302
https://github.com/openclaw/openclaw/commit/8deb9522f3d2680820588b190adb4a2a52f3670b
https://github.com/openclaw/openclaw/security/advisories/GHSA-9q7v-8mr7-g23p
https://www.vulncheck.com/advisories/openclaw-server-side-request-forgery-via-unguarded-fetch-in-marketplace-plugin-download
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
