MEDIUM
OpenClaw < 2026.3.31 - Server-Side Request Forgery via Marketplace Plugin Download Redirect
Published Apr 20, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.40%
Description
OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functionality that allows attackers to access internal resources by following unvalidated redirects. The marketplace.ts module fails to restrict redirect destinations during archive downloads, enabling remote attackers to redirect requests to arbitrary internal or external servers.
Affected products
-
- Version 0StatusaffectedConstraints<2026.3.31
- Version 2026.3.31StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.3.31
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.3.31 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://github.com/advisories/GHSA-vjx8-8p7h-82gr Advisory
- https://github.com/openclaw/openclaw/commit/2ce44ca6a1302b166a128abbd78f72114f2f4f52 patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-vjx8-8p7h-82gr vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-41297
- https://www.vulncheck.com/advisories/openclaw-server-side-request-forgery-via-marketplace-plugin-download-redirect third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-vjx8-8p7h-82gr | Advisory | |
| https://github.com/openclaw/openclaw/commit/2ce44ca6a1302b166a128abbd78f72114f2f4f52 | patch | |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-vjx8-8p7h-82gr | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-41297 | ||
| https://www.vulncheck.com/advisories/openclaw-server-side-request-forgery-via-marketplace-plugin-download-redirect | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 20, 2026
Updated Apr 21, 2026
Reserved Apr 20, 2026
Link CVE-2026-41297
CISA Vulnrichment
GHSA-VJX8-8P7H-82GR Updated Apr 21, 2026