CVE-2026-34504Disclosure(openclaw / openclaw)

LOWCVSS 6.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers to fetch internal URLs. A malicious or compromised fal relay can exploit unguarded image download fetches to expose internal service metadata and responses through the image pipeline.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-01); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-31: 1Mentions · 2026-04-01: 2Mentions · 2026-04-10: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-10: 103-3104-0104-10
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-311
Disclosure1
2026-04-012
Disclosure1General1
2026-04-101
Disclosure1
Full discourse4 posts
  • Vito Botta@vitobotta
    Disclosure

    From over a week ago but anyway, CVE-2026-34504 in OpenClaw's image generation pipeline is a reminder that AI agent frameworks inherit all the classic web vulnerabilities plus their own unique attack surface. An SSRF in the Fal provider means a malicious relay can have the agent fetch internal URLs and leak metadata through the generated output. I switched from OpenClaw to Hermes Agent a couple of weeks ago, and I need to explore in detail how Hermes handles this stuff.

    Post summary

    The text announces CVE-2026-34504 as an SSRF flaw in OpenClaw’s image‑generation pipeline, highlighting its implications for AI agent frameworks, but it offers no proof‑of‑concept, exploit, patch, or evidence of active exploitation.

    00000156
    922 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-34504 - High OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers to fetch internal URLs. A malic... https://www.thehackerwire.com/vulnerability/CVE-2026-34504/ https://t.co/OvTJ6jXZkQ

    Post summary

    The snippet announces CVE-2026-34504, describing a server‑side request forgery in OpenClaw and linking to a vulnerability article.

    0000057
    163 followersView on X
  • facts@leelup10
    General

    OPENCLAW CVE UPDATE LINKS ON CVE PAGE https://nvd.nist.gov/vuln/detail/CVE-2026-34504 🫡

    Post summary

    The post merely points to the NVD entry for CVE-2026-34504 without providing additional information.

    0000038
    11 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34504 OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers to fet… https://www.cve.org/CVERecord?id=CVE-2026-34504

    Post summary

    A new SSRF flaw (CVE-2026-34504) has been reported in OpenClaw versions older than 2026.3.28, affecting the fal provider image-generation-provider.ts component.

    0000080
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more