Server-Side Request Forgery (SSRF) in OpenClaw - #VU126834

 

Server-Side Request Forgery (SSRF) in OpenClaw - #VU126834

Published: April 22, 2026


Vulnerability identifier: #VU126834
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause server-side request forgery.

The vulnerability exists due to insufficient server-side request forgery validation in QQBot direct-upload media handling when forwarding attacker-controlled image URLs. A remote attacker can supply a crafted image URL to cause server-side request forgery.

The affected path is limited to QQBot outbound media handling and does not expose arbitrary local files.


Affected software

OpenClaw

Remediation

Install security update from vendor's website.

OpenClaw - update to 2026.4.20

External References

Related Security Bulletins