OpenClaw: Marketplace Plugin Download Follows Redirects Without SSRF Protection
Moderate severity
GitHub Reviewed
Published
Mar 31, 2026
in
openclaw/openclaw
•
Updated Apr 20, 2026
Description
Published to the GitHub Advisory Database
Apr 7, 2026
Reviewed
Apr 7, 2026
Last updated
Apr 20, 2026
Summary
Marketplace Plugin Download Follows Redirects Without SSRF Protection
Current Maintainer Triage
Affected Packages / Versions
openclaw(npm)2026.3.31<=2026.3.28>= 2026.3.31v2026.3.31Fix Commit(s)
2ce44ca6a1302b166a128abbd78f72114f2f4f52— 2026-03-31T12:59:42+01:00Release Process Note
2026.3.31.Thanks @AntAISecurityLab for reporting.
References