Description
OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across cross-origin redirects. Attackers can trigger redirects to different origins to intercept sensitive headers like X-Api-Key and Private-Token intended for the original destination.
Problem types
CWE-522 Insufficiently Protected Credentials
Product status
Any version before 2026.3.7
2026.3.7 (semver)
Credits
Elvin Latifli (@Rickidevs)
References
github.com/...enclaw/security/advisories/GHSA-6mgf-v5j7-45cr (GitHub Security Advisory (GHSA-6mgf-v5j7-45cr))
github.com/...ommit/46715371b0612a6f9114dffd1466941ac476cef5 (Patch Commit)
vulncheck.com/...n-header-leakage-via-cross-origin-redirects (VulnCheck Advisory)