CVE-2026-34504: OpenClaw < 2026.3.28 - Server-Side Request Forgery via Unguarded Image Download in fal Provider
OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers to fetch internal URLs. A malicious or compromised fal relay can exploit unguarded image download fetches to expose internal service metadata and responses through the image pipeline.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34504?
CVE-2026-34504 is classified as a critical severity vulnerability due to its potential to allow attackers to access internal URLs.
How do I fix CVE-2026-34504?
To fix CVE-2026-34504, upgrade OpenClaw to version 2026.3.28 or later, which includes the necessary security patches.
What type of vulnerability is CVE-2026-34504?
CVE-2026-34504 is a server-side request forgery vulnerability that affects the fal provider component in OpenClaw.
What can attackers do with CVE-2026-34504?
Attackers can exploit CVE-2026-34504 to fetch internal URLs, potentially compromising sensitive information.
Which versions of OpenClaw are affected by CVE-2026-34504?
OpenClaw versions prior to 2026.3.28 are affected by CVE-2026-34504.