CVE-2026-41297 — SSRF Vulnerability in OpenClaw Marketplace Plugin Downloads (CVSS 7.6)

The marketplace.ts module failed to restrict redirect destinations during archive downloads, allowing server-side request forgery. Attackers could redirect plugin downloads to malicious payloads.

CVE-2026-41297 — SSRF Vulnerability in OpenClaw Marketplace Plugin Downloads (CVSS 7.6)

Security researchers have identified a server-side request forgery flaw in the OpenClaw marketplace plugin download flow, tracked as CVE-2026-41297 and rated CVSS 7.6. The bug was found in the marketplace.ts module, where archive downloads did not properly restrict where redirects could lead, creating a path for attackers to steer a download request away from the intended source.

The issue matters because plugin installers usually expect to fetch an archive from a trusted location and then unpack it locally. In this case, a malicious redirect could cause the download process to request content from an attacker-controlled destination instead, which can turn a normal plugin install into a delivery channel for hostile payloads.

⚡ New to this?

This is a security bug in how OpenClaw downloaded plugin archives from its marketplace. SSRF, or server-side request forgery, means the software can be tricked into making a request to the wrong place, which can let an attacker swap in a malicious file.

Non-experts should care because plugins are often trusted software add-ons, and the install process is where that trust matters most. If the downloader follows a bad redirect, the system may fetch the attacker’s payload instead of the real plugin, which can create a supply-chain security problem.

🦞 OpenClaw angle

If you install plugins from the OpenClaw marketplace, this SSRF vulnerability could serve you a malicious payload instead of the real plugin. Update to v2026.4.24.

RedPacket Security, which reported the flaw, said the problem came down to insufficient validation of redirect targets during archive retrieval. That is a common class of mistake in networked software: a server is asked to fetch something on behalf of a user, but the software fails to verify that the remote location still matches the trusted source after redirects are followed.

SSRF, short for server-side request forgery, means the attacker tricks a server into making an HTTP request it did not intend to make. The risk is not limited to fetching the wrong file. Depending on how the server is connected, SSRF can also be used to reach internal systems, cloud metadata services, or other endpoints that are not exposed directly to the internet.

In plugin ecosystems, download paths are especially sensitive because the install process often runs with more trust than an ordinary web request. If the marketplace logic accepts redirected archive downloads without checking the final destination, an attacker who can influence the redirect chain may be able to substitute a malicious archive for the expected one.

The vulnerability was disclosed as CVE-2026-41297, and the severity score of 7.6 puts it in the high range. CVSS, or Common Vulnerability Scoring System, is a standard way to rate how serious a flaw is based on factors like how easy it is to exploit and how much damage it can cause.

According to the summary provided by the curator, the affected code sits in the marketplace.ts module, which handles marketplace download behavior. That points to the part of the product responsible for retrieving plugin archives, following redirects, and handing the downloaded content to the rest of the installation flow.

OpenClaw users who install marketplace plugins are the most directly affected because the attack path sits in the download process itself. A successful exploit could mean the system receives a payload from a malicious location instead of the intended plugin archive, which is exactly the kind of failure that supply-chain security teams try to prevent.

The issue was publicized by RedPacket Security on April 24, 2026, alongside guidance to move to version v2026.4.24, where the redirect handling has been addressed. The disclosure adds another example of how a small mistake in URL handling can turn a routine fetch operation into a trust problem across an entire plugin marketplace.

Source: RedPacket Security ↗

More from Security News