CVE-2026-28467: OpenClaw < 2026.2.2 - SSRF via Attachment Media URL Hydration
OpenClaw versions prior to 2026.2.2 contain a server-side request forgery vulnerability in attachment and media URL hydration that allows remote attackers to fetch arbitrary HTTP(S) URLs. Attackers who can influence media URLs through model-controlled sendAttachment or auto-reply mechanisms can trigger SSRF to internal resources and exfiltrate fetched response bytes as outbound attachments.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28467?
CVE-2026-28467 is classified as a medium severity vulnerability due to its potential for server-side request forgery.
How do I fix CVE-2026-28467?
To fix CVE-2026-28467, upgrade OpenClaw to version 2026.2.2 or later.
What kind of attack does CVE-2026-28467 enable?
CVE-2026-28467 enables remote attackers to perform server-side request forgery attacks.
Which versions of OpenClaw are affected by CVE-2026-28467?
OpenClaw versions prior to 2026.2.2 are affected by CVE-2026-28467.
How does CVE-2026-28467 affect attachment media URL hydration?
CVE-2026-28467 affects attachment media URL hydration by allowing unauthorized access to arbitrary HTTP(S) URLs.