All findings

endor-openclaw-image-tool-ssrf high

Endor Labs AI SAST finds SSRF in OpenClaw's Image tool

An AI-assisted dataflow review found that remote image URLs bypassed OpenClaw's SSRF guard, allowing requests to internal and restricted network targets.

Bug class
Server-side request forgery in remote media fetching
Affected codebase
OpenClaw
Credited system
Endor Labs AI SAST
Disclosed
February 17, 2026
Attribution
Direct source attribution
Severity
high
Source status: Endor Labs' primary research account ties the finding to its AI-SAST workflow. OpenClaw's GHSA independently documents the bug, reporter, fix commits, and patched 2026.2.2 release; no CVE is assigned.

Summary

OpenClaw’s Image tool accepted HTTP and HTTPS URLs but fetched them outside the project’s SSRF guard. An attacker able to control a tool invocation could make the agent request localhost, private-address, link-local, or other restricted network resources. The image-content requirement and GET-only behavior limit some common metadata attacks, but internal probing and access to image-returning services remain practical impacts.

OpenClaw routed remote media fetching through its hardened guard and released the fix in 2026.2.2. The advisory thanks the Endor researcher account and the research write-up identifies the AI-assisted discovery workflow.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.