CVE-2026-32913
OpenClaw before 2026.3.7 contains an improper header validation vulnerability in fetchWithSsrFGuard that forwards custom authorization headers across cross-origin redirects. Attackers can trigger redirects to different origins to intercept sensitive headers like X-Api-Key and Private-Token intended for the original destination.
- Affected products
- Openclaw
- Openclaw
- < 2026.3.7
- Fix
- Available
- CVSS 3.1
- 9.3 CRITICAL
- EPSS
- 0.3% (24th percentile)
- Weakness
- CWE-522
- NVD status
- Analyzed
- Published
- 2026-03-23
CVE-2026-32913 at NVD
1 known exploit for CVE-2026-32913
Proof-of-concept code and exploit modules indexed by Sploitus