Server-Side Request Forgery (SSRF) in OpenClaw - #VU126834
Published: April 22, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to cause server-side request forgery.
The vulnerability exists due to insufficient server-side request forgery validation in QQBot direct-upload media handling when forwarding attacker-controlled image URLs. A remote attacker can supply a crafted image URL to cause server-side request forgery.
The affected path is limited to QQBot outbound media handling and does not expose arbitrary local files.