CVE-2026-31989Disclosure(openclaw / openclaw)

LOWCVSS 6.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions prior to 2026.3.1 contain a server-side request forgery vulnerability in web_search citation redirect resolution that uses a private-network-allowing SSRF policy. An attacker who can influence citation redirect targets can trigger internal-network requests from the OpenClaw host to loopback, private, or internal destinations.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-19); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-19: 4Mentions · 2026-03-20: 1Technical Details · 2026-03-19: 303-1903-20
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-194
Disclosure3General1
2026-03-201
General1
Full discourse5 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-31989 📊 Severity: 7.4 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-31989 #CVE-2026-31989 #CVE #High  #CyberSecurity #InfoSec https://t.co/IPbyK4EObd

    Post summary

    The tweet merely announces CVE‑2026‑31989 with a high severity rating, providing no further technical or exploit details.

    0000029
    108 followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    🚨 6 high-severity CVEs dropped today for OpenClaw - the popular AI automation platform CVE-2026-28461 (7.5) - Memory exhaustion via webhook CVE-2026-31989 (7.4) - SSRF via web_search CVE-2026-27566 (7.1) - Allowlist bypass CVE-2026-31992 (7.1) - Exec-guard bypass CVE-2026-31994 (7.1) - Command injection CVE-2026-31998 (7.0) - Auth bypass Popular platforms = bigger targets. Track everything: http://vulntracker.io

    Post summary

    The tweet announces six high‑severity CVEs affecting OpenClaw, specifying each CVE ID, CVSS score, and a concise technical description of the vulnerability type.

    00000124
    433 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-31989 OpenClaw versions prior to 2026.3.1 contain a server-side request forgery vulnerability in web_search citation redirect resolution that uses a private-network-allowin… https://www.cve.org/CVERecord?id=CVE-2026-31989

    Post summary

    The text cites CVE-2026-31989 as a server‑side request forgery flaw in OpenClaw versions before 2026.3.1, providing only high‑level vulnerability details without evidence of PoC, exploitation, or patch information.

    0000099
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-31989 Server-Side Request Forgery in OpenClaw Web Search Citation Redirect Resolution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31989

    Post summary

    The entry references CVE‑2026‑31989 as an SSRF issue in OpenClaw Web Search Citation Redirect and links to a vulnerability details page, but provides no PoC, exploit, or patch information.

    0000040
    4.0K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-31989 - OpenClaw - OpenClaw - https://www.redpacketsecurity.com/cve-alert-cve-2026-31989-openclaw-openclaw/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-31989 #openclaw #

    Post summary

    The post announces CVE-2026-31989 and directs readers to a security site for details, but provides no technical specifics, exploit, or mitigation information.

    0000074
    3.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more