CVE-2026-32913Disclosure(openclaw / openclaw)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across cross-origin redirects. Attackers can trigger redirects to different origins to intercept sensitive headers like X-Api-Key and Private-Token intended for the original destination.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-522

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 5 mentions (2026-03-24); latest day: 1
  • 8 total mentions across 3 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline8 mentions / 3d
01345Mentions · 2026-03-23: 2Mentions · 2026-03-24: 5Mentions · 2026-04-07: 1Patch / Workaround · 2026-03-24: 2Patch / Workaround · 2026-04-07: 1Technical Details · 2026-03-23: 2Technical Details · 2026-03-24: 403-2303-2404-07
Signal classification3 categories
Disclosure
562.5%
Patch
225.0%
General
112.5%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-232
Disclosure2
2026-03-245
Disclosure3General1Patch1
2026-04-071
Patch1
Full discourse8 posts
  • Sentrinus@sentrinus
    General

    Your API just sent your private tokens to a stranger's server. You didn't get hacked. Your redirect handler did it for you. CVE-2026-32913 🧵 https://t.co/aQYb9i4Bzj

    Post summary

    The tweet highlights that CVE‑2026‑32913 caused private tokens to be transmitted to a third‑party server through a redirect handler, but offers no PoC, exploit code, patch info, or technical details.

    11110120
    7 followersView on X
  • Firmis Labs@FirmisLabs
    Patch

    CVE-2026-32913 · NIST 9.3/10 https://nvd.nist.gov/vuln/detail/CVE-2026-32913 ask your AI: "check if my project uses OpenClaw and if it's running a version before 2026.3.7" then: "update OpenClaw to version 2026.3.7 or later and verify my API calls still work correctly"

    Post summary

    The post references CVE‑2026‑32913 and recommends updating OpenClaw to version 2026.3.7 or newer, indicating the existence of a patch but providing no technical details or exploit evidence.

    1000027
    1 followersView on X
  • Sentrinus@sentrinus
    Disclosure

    When an app forwards Auth headers across domain redirects without validation, attackers intercept sensitive tokens. CVE-2026-32913 does exactly this. CVSS 7.7.

    Post summary

    The post reports CVE‑2026‑32913, noting that it allows leakage of auth tokens through cross‑domain redirects and assigns it a CVSS score of 7.7. No exploits, patches, or active use are mentioned.

    1000025
    7 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32913 Cross-Origin Header Leak in OpenClaw Before 2026.3.7 via Redirect Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32913

    Post summary

    CVE-2026-32913 is a disclosed vulnerability involving a Cross-Origin header leak via a redirect in OpenClaw versions prior to 2026.3.7, with no PoC, exploit, or patch information provided.

    0001059
    4.0K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-32913 — CVSS 9.3/10 █████████░ OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/jZuVTjpfWr

    Post summary

    CVE‑2026‑32913 is a critical improper header validation flaw in OpenClaw before version 2026.3.7, and a patch has now been released.

    1000036
    10 followersView on X
  • NCIIPC India@NCIIPC
    Disclosure

    An Improper Header Validation Vulnerability has been discovered in OpenClaw, an open-source autonomous AI agent. Users are advised to follow OEM Security Advisories to remain safe! #CVE-2026-32913 https://nvd.nist.gov/vuln/detail/CVE-2026-32913

    Post summary

    A newly identified improper header validation flaw in OpenClaw (CVE-2026-32913) is disclosed, with users urged to consult OEM security advisories for mitigation.

    00000175
    8.4K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-32913: CRITICAL] Warning: OpenClaw up to 2026.3.7 is vulnerable to improper header validation. Attackers can intercept sensitive headers during cross-origin redirects, risking exposure of data like...#cve,CVE-2026-32913,#cybersecurity https://cvefind.com/CVE-2026-32913

    Post summary

    The tweet announces a critical vulnerability (CVE‑2026‑32913) in OpenClaw and provides a short technical description, but offers no PoC, exploit code, or evidence of active exploitation.

    0000051
    606 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-32913 - Critical OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across cross-origin redirects. Attackers can... https://www.thehackerwire.com/vulnerability/CVE-2026-32913/ https://t.co/4HqG1jgrVK

    Post summary

    The post announces a critical CVE-2026-32913 vulnerability in OpenClaw, detailing improper header validation across redirects without providing evidence of exploitation or a patch.

    0000043
    145 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more