CVE-2026-100577
Last modified
CVE-2026-100577 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. OpenClaw versions before 2026.8.1 fail to validate video asset URLs returned by providers, allowing server-side requests to private destinations. A malicious or compromised provider can return private or loopback URLs to cause the CLI to make requests to internal services accessible from the OpenClaw host..
Description
OpenClaw versions before 2026.8.1 fail to validate video asset URLs returned by providers, allowing server-side requests to private destinations. A malicious or compromised provider can return private or loopback URLs to cause the CLI to make requests to internal services accessible from the OpenClaw host.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| OpenClaw | OpenClaw | < 2026.8.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-100577?
How severe is CVE-2026-100577?
How do I fix CVE-2026-100577?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-100571OpenClaw (npm package 'openclaw') versions >= 2026.6.6 and <…5.3
- CVE-2026-100572OpenClaw versions >= 2026.3.25 and < 2026.8.1 apply invalid-…5.3
- CVE-2026-100573OpenClaw versions before 2026.8.1 contain a sandbox policy b…3.3
- CVE-2026-100574OpenClaw (npm package 'openclaw') before 2026.8.1 contains a…5.9
- CVE-2026-100575OpenClaw Slack versions before 2026.8.1 fail to properly enf…8.8
- CVE-2026-100576OpenClaw versions before 2026.8.1 contain a server-side requ…5.4
- CVE-2026-100578OpenClaw (npm package `openclaw`) before 2026.7.1 fails to r…7.6
- CVE-2026-100579OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectl…7.6
- CVE-2026-10058ITS Intelligent SCADA System developed by ITP Technology has…4.8
- CVE-2026-100580OpenClaw (npm package 'openclaw') before 2026.7.1 improperly…8.8
- CVE-2026-100581OpenClaw for iOS before 2026.8.11 stores Gateway credentials…5.5
- CVE-2026-100582OpenClaw channel plugins (@openclaw/msteams, @openclaw/feish…6.5
Are you affected by CVE-2026-100577?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
