openclaw npm package versions <= 2026.2.17.Cron webhook delivery in src/gateway/server-cron.ts used fetch() directly, so webhook targets could reach private/metadata/internal endpoints without SSRF policy checks.
99db4d13e35851cdafThanks @Adam55A-code for reporting.
{
"nvd_published_at": "2026-02-21T10:16:13Z",
"github_reviewed_at": "2026-02-20T21:13:03Z",
"github_reviewed": true,
"severity": "MODERATE",
"cwe_ids": [
"CWE-918"
]
}