CVE-2026-34504 MEDIUM

CVE-2026-34504: OpenClaw < 2026.3.28 - Server-Side Request Forgery via Unguarded Image Download in fal Provider

Vendor Openclaw
Product OpenClaw
Weakness CWE-918 · SSRF
Published March 31, 2026
Last update March 31, 2026

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L

What the vulnerability does

01Description

OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers to fetch internal URLs. A malicious or compromised fal relay can exploit unguarded image download fetches to expose internal service metadata and responses through the image pipeline.

Key dates

02Disclosure timeline

March 31, 2026 CVE published
March 31, 2026 Record updated