#VU125116 Server-Side Request Forgery (SSRF) in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to cause gateway-host fetches to off-node destinations and disclose limited information, modify limited data, or affect availability.
The vulnerability exists due to server-side request forgery (SSRF) in camera URL payload handling when processing user-supplied camera.snap, camera.clip, camera_snap, or camera_clip URL fields. A remote user can supply a crafted URL to cause gateway-host fetches to off-node destinations and disclose limited information, modify limited data, or affect availability.
User interaction is required, and exploitation is limited to deployments where paired nodes are not fully trusted.