CVE-2026-101883
Received Received - Intake

Server-Side Request Forgery in OpenClaw Windows Node

Vulnerability report for CVE-2026-101883, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulnCheck

Description

OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability that bypasses URL risk evaluation enforced by canvas.navigate. Attackers with gateway or agent access can issue canvas.present to make the node's WebView send requests to localhost, private networks, or tailnet services from the user's machine.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openclaw windows_node to 2026.9.4 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Server-Side Request Forgery (SSRF) vulnerability in OpenClaw Windows Node through version 2026.9.4. It exists in the canvas.present capability, which allows attackers with gateway or agent access to bypass URL risk evaluation enforced by canvas.navigate. This lets the node's WebView send requests to localhost, private networks, or tailnet services from the user's machine.

Detection Guidance

To detect this SSRF vulnerability in OpenClaw Windows Node, monitor network traffic from the application for unexpected requests to localhost, private networks, or tailnet services. Check logs for canvas.present calls bypassing URL validation. Inspect WebView2 traffic for internal IP access attempts.

Impact Analysis

Attackers could exploit this to force the node to load internal services like 127.0.0.1, LAN devices, Tailscale peers, or cloud metadata endpoints without proper validation. This enables request forgery, CSRF attacks, port scanning, and unauthorized access to internal-only endpoints.

Mitigation Strategies

Immediately update OpenClaw Windows Node to the latest patched version. If patching is not possible, restrict network access for the application, block internal IP ranges at the firewall, and disable canvas.present capability until a fix is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101883. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart