GHSA-pg2v-8xwh-qhcc: OpenClaw affected by SSRF in optional Tlon (Urbit) extension authentication
The optional Tlon (Urbit) extension previously accepted a user-provided base URL for authentication and used it to construct an outbound HTTP request, enabling server-side request forgery (SSRF) in affected deployments.
References
Code Behaviors & Features
Detect and mitigate GHSA-pg2v-8xwh-qhcc with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →