Skip to main content
EPSS 0.4%top 64%

Openclaw cli: OpenClaw affected by SSRF in optional Tlon (Urbit) extension authentication (CVE-2026-28476)

0
High
Published: 08/13/2026 (08/13/2026, 17:21:32 UTC)
Source: GCVE Database
Product: openclaw-cli

Description

The openclaw-cli package is affected by a server-side request forgery (SSRF) vulnerability in its optional Tlon (Urbit) extension authentication. This vulnerability arises because the extension accepted a user-provided base URL for authentication and used it to make outbound HTTP requests without sufficient validation. Only deployments that have installed and configured the Tlon extension and allow attackers to influence the Urbit URL are impacted. The issue is fixed in version 2026.2.14, which introduces URL validation and an SSRF guard blocking private/internal hosts by default.

CVSS v3.1

Score 8.3high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

Affected software

Homebrewmore threats →ghsa
openclaw-cli
pkg:brew/openclaw-cli
Affected versions
>=2026.1.29 <2026.2.14

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/04/2026, 13:08:52 UTC

Technical Analysis

The optional Tlon (Urbit) extension in openclaw-cli versions up to 2026.2.13 accepted a user-supplied base URL for authentication and used it to construct outbound HTTP requests, enabling SSRF. This vulnerability allows an attacker who can influence the configured Urbit URL to induce the gateway to make HTTP requests to arbitrary hosts, including internal network addresses. The fix in version 2026.2.14 adds validation and normalization of the base URL and implements an SSRF guard that blocks private/internal hosts by default, with an opt-in option to allow private network access.

Potential Impact

An attacker able to control the Urbit URL configuration in deployments using the Tlon extension can cause the system to make HTTP requests to attacker-chosen hosts, potentially including internal network resources. This can lead to information disclosure, internal network scanning, or other SSRF-related impacts. Deployments not using the Tlon extension or where the Urbit URL cannot be influenced by untrusted users are not affected.

Mitigation Recommendations

A patch is available in openclaw-cli version 2026.2.14, which should be applied once released. This update validates and normalizes the base URL and includes an SSRF guard blocking private/internal hosts by default. Until the patch is applied, ensure that untrusted users cannot modify the Urbit URL configuration or disable the Tlon extension if not needed.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
BREW-openclaw-cli-CVE-2026-28476
Osv Schema Version
1.7.3
Ecosystems
["Homebrew"]
Cvss Version
3.1

Threat ID: 6ac245c612601ec6a3167e8e

Added to database: 10/04/2026, 12:25:42 UTC

Last enriched: 10/04/2026, 13:08:52 UTC

Last updated: 10/04/2026, 16:08:37 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses