OpenClaw hardened cron webhook delivery against SSRF
Moderate severity
GitHub Reviewed
Published
Feb 20, 2026
in
openclaw/openclaw
•
Updated Feb 23, 2026
Description
Published to the GitHub Advisory Database
Feb 20, 2026
Reviewed
Feb 20, 2026
Published by the National Vulnerability Database
Feb 21, 2026
Last updated
Feb 23, 2026
Affected Packages / Versions
openclawnpm package versions<= 2026.2.17.Vulnerability
Cron webhook delivery in
src/gateway/server-cron.tsusedfetch()directly, so webhook targets could reach private/metadata/internal endpoints without SSRF policy checks.Fix Commit(s)
99db4d13e35851cdafThanks @Adam55A-code for reporting.
References