Back to search
CVE-2026-27488
Published: Feb 21, 2026
Modified: Feb 24, 2026
PUBLISHED
Description
OpenClaw is a personal AI assistant. In versions 2026.2.17 and below, Cron webhook delivery in src/gateway/server-cron.ts uses fetch() directly, so webhook targets can reach private/metadata/internal endpoints without SSRF policy checks. This issue was fixed in version 2026.2.19.
| Vendor | Product | Versions |
|---|---|---|
openclaw | openclaw | affected < 2026.2.19 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now