CVE-2026-44117

OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in QQBot direct media upload that skips URL validation. Attackers can bypass SSRF protections by sending crafted image URLs to uploadC2CMedia and uploadGroupMedia endpoints to relay unintended requests.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

07 May 2026, 17:07

Type Values Removed Values Added
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
First Time Openclaw
Openclaw openclaw
References () https://github.com/openclaw/openclaw/commit/49db424c8001f2f419aad85f434894d8d85c1a09 - () https://github.com/openclaw/openclaw/commit/49db424c8001f2f419aad85f434894d8d85c1a09 - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-c4qg-j8jg-42q5 - () https://github.com/openclaw/openclaw/security/advisories/GHSA-c4qg-j8jg-42q5 - Mitigation, Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-server-side-request-forgery-in-qqbot-direct-media-upload - () https://www.vulncheck.com/advisories/openclaw-server-side-request-forgery-in-qqbot-direct-media-upload - Third Party Advisory

06 May 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-06 20:16

Updated : 2026-05-07 17:07


NVD link : CVE-2026-44117

Mitre link : CVE-2026-44117

CVE.ORG link : CVE-2026-44117


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-918

Server-Side Request Forgery (SSRF)