{"id":"CVE-2026-34504","title":"OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers to fetch internal URLs","summary":"OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers to fetch internal URLs. A malicious or compromised fal relay can exploit ungu…","severity":"high","cvss":8.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L","cwe":["CWE-918"],"vendor":"openclaw","product":"openclaw","affected":["openclaw < 2026.3.28"],"patched":["openclaw 2026.3.28"],"published":"2026-03-31","updated":"2026-07-24","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-34504","references":[{"url":"https://github.com/openclaw/openclaw/commit/80d1e8a11a2ac118c7f7a70bba9c862b6141d928","label":"disclosure@vulncheck.com"},{"url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-qxgf-hmcj-3xw3","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/openclaw-server-side-request-forgery-via-unguarded-image-download-in-fal-provider","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"epss":0.00227,"epssPercentile":0.13621,"ingestedAt":"2026-07-24T21:39:13.598Z","slug":"CVE-2026-34504","body":"## Overview\n\nOpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers to fetch internal URLs. A malicious or compromised fal relay can exploit unguarded image download fetches to expose internal service metadata and responses through the image pipeline.\n\n## Affected\n\n- `openclaw < 2026.3.28`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `openclaw 2026.3.28`","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":45.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}