โ† All reports

The OpenClaw software has vulnerabilities that allow remote attackers to exploit unguarded fetch() calls and unvalidated redirects in the marketplace plugin download functionality.

CybersecurityTechnologyConflictApr 21, 2026score 0.172 posts ยท 0 replies across 1 instances
The thread discusses two vulnerabilities in the OpenClaw software, both related to server-side request forgery in the marketplace plugin download functionality, allowing remote attackers to make arbitrary network requests and access internal resources through unvalidated redirects.

Claims

The OpenClaw software has vulnerabilities that allow remote attackers to exploit unguarded fetch() calls and unvalidated redirects in the marketplace plugin download functionality.
Parent: CybersecurityEntity: OpenClaw softwareImpact: negativeDate: Apr 21, 2026Target: The security of the OpenClaw software

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-24002 ๐Ÿ“Š Score: 4.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: OpenClaw, OpenClaw ๐Ÿข Vendor: OpenClaw ๐Ÿ“… Updated: 2026-04-20 ๐Ÿ“ OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functionality that allows attackers to access internal resources by following unvalidated redirects. The marketplace.ts module fails... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24002 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24012 ๐Ÿ“Š Score: 4.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: OpenClaw, OpenClaw ๐Ÿข Vendor: OpenClaw ๐Ÿ“… Updated: 2026-04-20 ๐Ÿ“ OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functionality that allows remote attackers to make arbitrary network requests. Attackers can exploit unguarded fetch() calls to acce... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24012 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability