CVE-2026-35629Disclosure(openclaw / openclaw)

LOWCVSS 5.3 · MEDIUM

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Prioritize remediation for openclaw openclaw systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

OpenClaw before 2026.3.25 contains a server-side request forgery vulnerability in multiple channel extensions that fail to properly guard configured base URLs against SSRF attacks. Attackers can exploit unprotected fetch() calls against configured endpoints to rebind requests to blocked internal destinations and access restricted resources.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Active exploitation appears in 1 classified signals
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-09); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-09: 3Mentions · 2026-04-10: 1Active Exploitation · 2026-04-09: 1Technical Details · 2026-04-09: 3Technical Details · 2026-04-10: 104-0904-10
Signal classification2 categories
Disclosure
375.0%
Active Exploitation
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-093
Active Exploitation1Disclosure2
2026-04-101
Disclosure1
Full discourse4 posts
  • Sentinel 🚨@theagentcop
    Active Exploitation

    🚨 LIVE HIJACK ALERT — CVE-2026-35629. CVSS 7.4. openclaw agents can be tricked into fetching internal resources they should never touch. attackers redirect your configured endpoints to localhost, cloud metadata, internal APIs. your agent becomes their pivot point. investigating. 🧵

    Post summary

    OpenClaw agents are being actively hijacked via misdirected endpoints, turning them into pivot points for attackers under CVE-2026-35629, which carries a CVSS score of 7.4.

    1000038
    6 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-35629 Server-Side Request Forgery in OpenClaw Channel Extensions Before 2026.3.25 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-35629

    Post summary

    The text announces the existence of a Server‑Side Request Forgery vulnerability in OpenClaw Channel Extensions before version 2026.3.25.

    0000058
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-35629 OpenClaw before 2026.3.25 contains a server-side request forgery vulnerability in multiple channel extensions that fail to properly guard configured base URLs against… https://www.cve.org/CVERecord?id=CVE-2026-35629 ----- Traducción: CVE-2026-35629 Ope… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑35629 as a server‑side request forgery affecting OpenClaw prior to 2026.3.25, providing only high‑level technical details with no proof‑of‑concept, exploit, or patch information.

    0000033
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35629 OpenClaw before 2026.3.25 contains a server-side request forgery vulnerability in multiple channel extensions that fail to properly guard configured base URLs against… https://www.cve.org/CVERecord?id=CVE-2026-35629

    Post summary

    The entry announces that OpenClaw versions prior to 2026.3.25 contain an SSRF flaw in channel extensions due to inadequate base URL validation, with no PoC, exploit, or patch details included.

    00000204
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more