
CVE-2026-41297 OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functionality that allows attackers to access intern… https://www.cve.org/CVERecord?id=CVE-2026-41297
Post summary
OpenClaw prior to version 2026.3.31 contains a server‑side request forgery vulnerability in the marketplace plugin download feature, allowing attackers to access internal resources.

