Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pg8g-f2hf-x82m

Опубликовано: 09 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

Duplicate Advisory: OpenClaw: fetchWithSsrFGuard replays unsafe request bodies across cross-origin redirects

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-qx8j-g322-qj6m. This link is maintained to preserve external references.

Original Description

OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGuard that allows unsafe request bodies to be resent across cross-origin redirects. Attackers can exploit this by triggering redirects to exfiltrate sensitive request data or headers to unintended origins.

Пакеты

Наименование

openclaw

npm
Затронутые версииВерсия исправления

< 2026.4.8

2026.4.8

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-601

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-601