
CVE-2026-28467 OpenClaw versions prior to 2026.2.2 contain a server-side request forgery vulnerability in attachment and media URL hydration that allows remote attackers to fetch ar… https://www.cve.org/CVERecord?id=CVE-2026-28467
Post summary
The text reports a server‑side request forgery vulnerability in OpenClaw versions before 2026.2.2 that lets remote attackers fetch arbitrary content, linking to the official CVE record.
