Marketplace Plugin Download Follows Redirects Without SSRF Protection
openclaw (npm)2026.3.31<=2026.3.28>= 2026.3.31v2026.3.312ce44ca6a1302b166a128abbd78f72114f2f4f52 — 2026-03-31T12:59:42+01:002026.3.31.Thanks @AntAISecurityLab for reporting.
{
"cwe_ids": [
"CWE-918"
],
"github_reviewed": true,
"github_reviewed_at": "2026-04-07T18:10:45Z",
"nvd_published_at": "2026-04-21T00:16:30Z",
"severity": "MODERATE"
}