← Zuruck zu CVEs
CVE-2026-32037
MEDIUM6.0
Beschreibung
OpenClaw versions prior to 2026.2.22 fail to consistently validate redirect chains against configured mediaAllowHosts allowlists during MSTeams media downloads. Attackers can supply or influence attachment URLs to force redirects to non-allowlisted targets, bypassing SSRF boundary controls.
CVE Details
CVSS v3.1 Bewertung6.0
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L
AngriffsvektorNETWORK
KomplexitatHIGH
Erforderliche PrivilegienLOW
BenutzerinteraktionNONE
Veroffentlicht3/19/2026
Zuletzt geandert3/23/2026
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
openclaw:openclaw
Schwachen (CWE)
CWE-918
Referenzen
https://github.com/openclaw/openclaw/commit/73d93dee64127a26f1acd09d0403b794cdeb4f5c(disclosure@vulncheck.com)
https://github.com/openclaw/openclaw/commit/b34097f62df9d1960cc22600269cd3f3284e2124(disclosure@vulncheck.com)
https://github.com/openclaw/openclaw/security/advisories/GHSA-w76h-8m22-hpgh(disclosure@vulncheck.com)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.