CVE-2026-32913
CRITICALOpenClaw < 2026.3.7 - Custom Authorization Header Leakage via Cross-Origin Redirects
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-32913. PoCs published by Rickidevs.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2026-32913, an information leakage vulnerability in OpenClaw's `fetchWithSsrFGuard()` function. The issue arises from an incomplete denylist of sensitive headers during cross-origin redirects, allowing custom authorization headers to be forwarded to attacker-controlled destinations.
Description
OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across cross-origin redirects. Attackers can trigger redirects to different origins to intercept sensitive headers like X-Api-Key and Private-Token intended for the original destination.
Exploits (1)
This repository provides a detailed technical analysis of CVE-2026-32913, an information leakage vulnerability in OpenClaw's `fetchWithSsrFGuard()` function. The issue arises from an incomplete denylist of sensitive headers during cross-origin redirects, allowing custom authorization headers to be forwarded to attacker-controlled destinations.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N