LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-32037

openclaw · openclaw

Published
CVSS6
Severitymedium
WeaknessCWE-918
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L

Description

OpenClaw versions prior to 2026.2.22 fail to consistently validate redirect chains against configured mediaAllowHosts allowlists during MSTeams media downloads. Attackers can supply or influence attachment URLs to force redirects to non-allowlisted targets, bypassing SSRF boundary controls.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-32037

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-32037.