{"id":"CVE-2026-27488","aliases":["GHSA-w45g-5746-x9fp"],"url":"https://o3.security/vulnerability/CVE-2026-27488","summary":"OpenClaw hardened cron webhook delivery against SSRF","details":"## Affected Packages / Versions\n\n- `openclaw` npm package versions `<= 2026.2.17`.\n\n## Vulnerability\nCron webhook delivery in `src/gateway/server-cron.ts` used `fetch()` directly, so webhook targets could reach private/metadata/internal endpoints without SSRF policy checks.\n\n## Fix Commit(s)\n- `99db4d13e`\n- `35851cdaf`\n\nThanks @Adam55A-code for reporting.","published":"2026-02-21T09:49:04.956Z","modified":"2026-08-12T03:51:37.079446467Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"openclaw","fixedVersion":"2026.2.19"}],"fix":{"url":"https://github.com/openclaw/openclaw/commit/99db4d13e5c139883ef0def9ff963e9273179655","label":"openclaw/openclaw@99db4d1"},"references":[{"type":"WEB","url":"https://github.com/openclaw/openclaw/releases/tag/v2026.2.19"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27488.json"},{"type":"ADVISORY","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-w45g-5746-x9fp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27488"},{"type":"FIX","url":"https://github.com/openclaw/openclaw/commit/99db4d13e5c139883ef0def9ff963e9273179655"},{"type":"PACKAGE","url":"https://github.com/openclaw/openclaw"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:37.079446467Z"}}