CVE-2026-28476 | OpenClaw up to 2026.2.13 server-side request forgery (GHSA-pg2v-8xwh-qhcc)
A vulnerability was found in OpenClaw up to 2026.2.13. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation results in server-side request forgery.
This vulnerability is cataloged as CVE-2026-28476. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.