CVE-2026-40037
Severity CVSS v4.0:
HIGH
Type:
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
08/04/2026
Last modified:
08/04/2026
Description
OpenClaw before 2026.3.31 (patched in 2026.4.8) contains a request body replay vulnerability in fetchWithSsrFGuard that allows unsafe request bodies to be resent across cross-origin redirects. Attackers can exploit this by triggering redirects to exfiltrate sensitive request data or headers to unintended origins.
Impact
Base Score 4.0
7.10
Severity 4.0
HIGH
Base Score 3.x
6.50
Severity 3.x
MEDIUM



