Vulnerability Description
OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across cross-origin redirects. Attackers can trigger redirects to different origins to intercept sensitive headers like X-Api-Key and Private-Token intended for the original destination.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openclaw | Openclaw | < 2026.3.7 |
Related Weaknesses (CWE)
References
- https://github.com/openclaw/openclaw/commit/46715371b0612a6f9114dffd1466941ac476Patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-6mgf-v5j7-45crVendor Advisory
- https://vulncheck.com/advisories/openclaw-mar-custom-authorization-header-leakagThird Party Advisory
FAQ
What is CVE-2026-32913?
CVE-2026-32913 is a vulnerability with a CVSS score of 9.3 (CRITICAL). OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across cross-origin redirects. Attackers can trigger redi...
How severe is CVE-2026-32913?
CVE-2026-32913 has been rated CRITICAL with a CVSS base score of 9.3/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-32913?
Check the references section above for vendor advisories and patch information. Affected products include: Openclaw Openclaw.