The OpenClaw software has vulnerabilities that allow remote attackers to exploit unguarded fetch() calls and unvalidated redirects in the marketplace plugin download functionality.
Claims
The OpenClaw software has vulnerabilities that allow remote attackers to exploit unguarded fetch() calls and unvalidated redirects in the marketplace plugin download functionality.
Parent: CybersecurityEntity: OpenClaw softwareImpact: negativeDate: Apr 21, 2026Target: The security of the OpenClaw software
Source posts
๐จ EUVD-2026-24002
๐ Score: 4.8/10 (CVSS v3.1)
๐ฆ Product: OpenClaw, OpenClaw
๐ข Vendor: OpenClaw
๐
Updated: 2026-04-20
๐ OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functionality that allows attackers to access internal resources by following unvalidated redirects. The marketplace.ts module fails...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24002
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24012
๐ Score: 4.8/10 (CVSS v3.1)
๐ฆ Product: OpenClaw, OpenClaw
๐ข Vendor: OpenClaw
๐
Updated: 2026-04-20
๐ OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functionality that allows remote attackers to make arbitrary network requests. Attackers can exploit unguarded fetch() calls to acce...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24012
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability