OpenClaw hardened cron webhook delivery against SSRF
Moderate severity
GitHub Reviewed
Published
Feb 20, 2026
in
openclaw/openclaw
•
Updated Feb 20, 2026
Description
Published to the GitHub Advisory Database
Feb 20, 2026
Reviewed
Feb 20, 2026
Last updated
Feb 20, 2026
Affected Packages / Versions
openclawnpm package versions<= 2026.2.17.Vulnerability
Cron webhook delivery in
src/gateway/server-cron.tsusedfetch()directly, so webhook targets could reach private/metadata/internal endpoints without SSRF policy checks.Fix Commit(s)
99db4d13e35851cdafThanks @Adam55A-code for reporting.
References