CVE-2026-31989: Openclaw

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

OpenClaw versions prior to 2026.3.1 contain a server-side request forgery vulnerability in web_search citation redirect resolution that uses a private-network-allowing SSRF policy. An attacker who can influence citation redirect targets can trigger internal-network requests from the OpenClaw host to loopback, private, or internal destinations.

Affected products

  • Openclaw Openclaw: before 2026.3.1 (fixed in 2026.3.1)

Published 2026-03-19. Last modified 2026-06-17.