SSRF via Unguarded fetch() in Marketplace Plugin Download and Ollama Model Discovery
openclaw (npm)2026.3.31<=2026.3.28>= 2026.3.31v2026.3.318deb9522f3d2680820588b190adb4a2a52f3670b — 2026-03-30T20:08:38+01:00OpenClaw thanks @tdjackey for reporting.
{
"severity": "MODERATE",
"github_reviewed": true,
"nvd_published_at": null,
"cwe_ids": [
"CWE-918"
],
"github_reviewed_at": "2026-04-02T21:22:56Z"
}