Untriaged
Permalink
CVE-2026-34504
8.3 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): CHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): LOW
OpenClaw < 2026.3.28 - Server-Side Request Forgery via Unguarded Image Download in fal Provider
OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers to fetch internal URLs. A malicious or compromised fal relay can exploit unguarded image download fetches to expose internal service metadata and responses through the image pipeline.
References
-
GitHub Security Advisory (GHSA-qxgf-hmcj-3xw3) third-party-advisory
-
Patch Commit patch
Affected products
OpenClaw
- ==2026.3.28
- <2026.3.28
Package maintainers
-
@chrisportela Chris Portela <chris@chrisportela.com>