Back

MEDIUM

OpenClaw < 2026.4.5 - Second-hop SSRF via CDP /json/version WebSocket URL

Published May 6, 2026

Description

OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in the CDP /json/version WebSocket endpoint that allows attackers to pivot to untrusted second-hop targets. The webSocketDebuggerUrl response field is not properly validated, enabling attackers to redirect connections to arbitrary hosts and perform SSRF-style attacks.

Affected products

Remediation

No remediation recorded yet.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published May 6, 2026
Updated May 7, 2026
Reserved May 1, 2026
CISA Vulnrichment
Updated May 7, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulnCheck
Published May 6, 2026
Updated May 7, 2026
Exploited since n/a
EUVD-2026-28164 GHSA-F7FH-QG34-X2XH