CyberRota
Back to database

CVE-2026-41302

HIGH · CVSS 7.6 EPSS 0.04% Public Exploit

Source: NVD + CISA KEV + EPSS · Published: 2026-04-21 · Last synced: 2026-05-18

CyberRota Analysis

Uzaktan istismar edilebilir olabilir.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-41302
Severity
HIGH
CVSS
7.6
EPSS
0.04%

Original NVD Description

OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functionality that allows remote attackers to make arbitrary network requests. Attackers can exploit unguarded fetch() calls to access internal resources or interact with external services on behalf of the affected system.