CVE-2026-44116

OpenClaw before 2026.4.22 contains a server-side request forgery vulnerability in the Zalo plugin's sendPhoto function that fails to validate outbound photo URLs through the SSRF guard. Attackers can bypass SSRF protection by providing malicious photo URLs to the Zalo Bot API, enabling unauthorized access to internal resources.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

07 May 2026, 17:07

Type Values Removed Values Added
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
References () https://github.com/openclaw/openclaw/commit/a65eb1b864b7630c1242a82de9e5799b80583c3f - () https://github.com/openclaw/openclaw/commit/a65eb1b864b7630c1242a82de9e5799b80583c3f - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-2hh7-c75g-qj2r - () https://github.com/openclaw/openclaw/security/advisories/GHSA-2hh7-c75g-qj2r - Mitigation, Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-server-side-request-forgery-in-zalo-photo-url-validation - () https://www.vulncheck.com/advisories/openclaw-server-side-request-forgery-in-zalo-photo-url-validation - Third Party Advisory
First Time Openclaw
Openclaw openclaw

06 May 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-06 20:16

Updated : 2026-05-07 17:07


NVD link : CVE-2026-44116

Mitre link : CVE-2026-44116

CVE.ORG link : CVE-2026-44116


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-918

Server-Side Request Forgery (SSRF)