Summary
OpenClaw’s Image tool accepted HTTP and HTTPS URLs but fetched them outside the project’s SSRF guard. An attacker able to control a tool invocation could make the agent request localhost, private-address, link-local, or other restricted network resources. The image-content requirement and GET-only behavior limit some common metadata attacks, but internal probing and access to image-returning services remain practical impacts.
OpenClaw routed remote media fetching through its hardened guard and released the fix in 2026.2.2. The advisory thanks the Endor researcher account and the research write-up identifies the AI-assisted discovery workflow.
References
- Endor Labs: six OpenClaw vulnerabilities
- OpenClaw advisory: GHSA-56f2-hvwg-5743
- OpenClaw 2026.2.2 release
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.