#VU125226 Server-Side Request Forgery (SSRF) in OpenClaw - CVE-2026-34504
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in extensions/fal/image-generation-provider.ts when downloading returned image URLs from the fal provider. A remote attacker can cause the gateway to fetch internal URLs to disclose sensitive information.
Exploitation requires a malicious or compromised fal relay.