HarborGuard / CVE
Back to search
HIGHCVE-2026-40037Published Modified CNA VulnCheck

CVE-2026-40037: OpenClaw < 2026.3.31 - Unsafe Request Body Replay via fetchWithSsrFGuard Cross-Origin Redirects

OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGuard that allows unsafe request bodies to be resent across cross-origin redirects. Attackers can exploit this by triggering redirects to exfiltrate sensitive request data or headers to unintended origins.

Metrics

CVSS v4.0
7.1
Severity
HIGH
Fixed in
2026.4.8
Affected Products
1

Fix available

2026.4.8
Patch commits
Affected packages
  • OpenClaw / OpenClaw
    < 2026.4.8 (from 0)
    Fixed in 2026.4.8
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N