OpenClaw: SSRF via Unguarded `fetch()` in Marketplace Plugin Download and Ollama Model Discovery
Moderate severity
GitHub Reviewed
Published
Mar 31, 2026
in
openclaw/openclaw
•
Updated Apr 21, 2026
Description
Published to the GitHub Advisory Database
Apr 2, 2026
Reviewed
Apr 2, 2026
Last updated
Apr 21, 2026
Summary
SSRF via Unguarded
fetch()in Marketplace Plugin Download and Ollama Model DiscoveryCurrent Maintainer Triage
Affected Packages / Versions
openclaw(npm)2026.3.31<=2026.3.28>= 2026.3.31v2026.3.31Fix Commit(s)
8deb9522f3d2680820588b190adb4a2a52f3670b— 2026-03-30T20:08:38+01:00OpenClaw thanks @tdjackey for reporting.
References