CVE-2026-34504High· 8.3▾ TwilightOpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers to fetch internal URLs. A malicious or compromised fal relay can exploit ungu…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 24.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers to fetch internal URLs. A malicious or compromised fal relay can exploit unguarded image download fetches to expose internal service metadata and responses through the image pipeline.
openclaw < 2026.3.28Upgrade past the affected range:
openclaw 2026.3.28Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53812Medium· 7.7OpenClaw's browser act interactions could bypass private-network navigation checks
GHSA-vqx6-6j84-2794Medium· 6.5Duplicate Advisory: Hostname checks could treat trailing-dot hosts inconsistently
CVE-2026-53859Medium· 6.5OpenClaw: Hostname checks could treat trailing-dot hosts inconsistently
CVE-2025-68616High· 7.5WeasyPrint helps web developers to create PDF documents
CVE-2026-94094Medium· 4.3A flaw has been found in OpenClaw up to 2026.9.5
CVE-2026-32896Medium· 4.8The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication path that allows unauthenticated webhook events in certain reverse-proxy or local routing configurations