Openclaw cli: OpenClaw affected by SSRF in Image Tool Remote Fetch
Description
OpenClaw CLI versions up to 2026.2.1 contain a server-side request forgery (SSRF) vulnerability in the Image tool's remote fetch functionality. This flaw allows attackers to make HTTP requests to internal or restricted network targets by supplying crafted URLs. The vulnerability is patched in version 2026.2.2 and later. Exploitation requires attacker control over the Image tool invocation and is limited by media-type validation and request constraints. The SSRF can enable internal network probing and access to unauthenticated internal HTTP endpoints.
CVSS v3.1
Score 7.6high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A SSRF vulnerability exists in the OpenClaw CLI Image tool in versions up to 2026.2.1, where http(s) URLs are fetched without SSRF protections. This allows attackers to force the tool to make arbitrary HTTP GET requests to internal or restricted network resources, including localhost, RFC1918, link-local, and cloud metadata endpoints. The vulnerability was fixed by adding SSRF guards such as private/internal IP and hostname blocking, redirect hardening, and DNS pinning in version 2026.2.2. Exploitation requires attacker-controlled invocation of the Image tool with untrusted image arguments. The tool expects image content, limiting some impact, but SSRF remains a significant risk for internal network reconnaissance and potential chaining with other vulnerabilities.
Potential Impact
Successful exploitation can lead to unauthorized HTTP requests from the vulnerable system to internal or restricted network targets, potentially exposing sensitive internal services or data. Confidentiality impact is primarily on internal endpoints that return image data, while other endpoints returning non-image data may fail validation. SSRF can facilitate internal network probing and access to unauthenticated internal HTTP services. The vulnerability has a CVSS score of 7.6 (high severity), indicating a significant risk of confidentiality, integrity, and availability impacts.
Mitigation Recommendations
A patch is available in OpenClaw CLI version 2026.2.2 and later that implements SSRF protections including IP and hostname blocking, redirect hardening, and DNS pinning. Users should upgrade to version 2026.2.2 or later to remediate this vulnerability. No additional mitigations are indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-openclaw-cli-GHSA-56f2-hvwg-5743
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 3.1
Threat ID: 6ac2458912601ec6a31640a8
Added to database: 10/04/2026, 12:24:41 UTC
Last enriched: 10/04/2026, 12:33:45 UTC
Last updated: 10/04/2026, 12:33:45 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.