
CVE-2026-41302 OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functionality that allows remote attackers to make a… https://www.cve.org/CVERecord?id=CVE-2026-41302
Post summary
The statement discloses a server‑side request forgery flaw in OpenClaw’s marketplace plugin, providing basic technical details but no evidence of active exploitation or mitigation.
