CVE-2026-34504

HIGH

OpenClaw < 2026.3.28 - Server-Side Request Forgery via Unguarded Image Download in fal Provider

Title source: cna

Description

OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers to fetch internal URLs. A malicious or compromised fal relay can exploit unguarded image download fetches to expose internal service metadata and responses through the image pipeline.

Scores

CVSS v3 8.3
EPSS 0.0005
EPSS Percentile 15.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (4)
npm/openclaw 0 - 2026.3.28npm
OpenClaw/OpenClaw < 2026.3.28
openclaw/openclaw < 2026.3.28
OpenClaw/OpenClaw 2026.3.28
Published Mar 31, 2026
Tracked Since Mar 31, 2026