{"id":"CVE-2026-28467","aliases":["GHSA-wfp2-v9c7-fh79"],"url":"https://o3.security/vulnerability/CVE-2026-28467","summary":"OpenClaw < 2026.2.2 - SSRF via Attachment Media URL Hydration","details":"OpenClaw versions prior to 2026.2.2 contain a server-side request forgery vulnerability in attachment and media URL hydration that allows remote attackers to fetch arbitrary HTTP(S) URLs. Attackers who can influence media URLs through model-controlled sendAttachment or auto-reply mechanisms can trigger SSRF to internal resources and exfiltrate fetched response bytes as outbound attachments.","published":"2026-03-05T21:59:43.489Z","modified":"2026-08-12T03:51:46.967829118Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"openclaw","fixedVersion":"2026.2.2"}],"fix":{"url":"https://github.com/openclaw/openclaw/commit/81c68f582d4a9a20d9cca9f367d2da9edc5a65ae","label":"openclaw/openclaw@81c68f5"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28467.json"},{"type":"ADVISORY","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-wfp2-v9c7-fh79"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28467"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/openclaw-ssrf-via-attachment-media-url-hydration"},{"type":"FIX","url":"https://github.com/openclaw/openclaw/commit/81c68f582d4a9a20d9cca9f367d2da9edc5a65ae"},{"type":"FIX","url":"https://github.com/openclaw/openclaw/commit/9bd64c8a1f91dda602afc1d5246a2ff2be164647"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:46.967829118Z"}}