Server-Side Request Forgery (SSRF) in OpenClaw - #VU127184
Published: April 23, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to perform server-side request forgery.
The vulnerability exists due to insufficient destination validation in the Zalo plugin outbound photo URL handling when processing an attacker-controlled outbound photo URL for the Zalo Bot API. A remote attacker can supply a crafted outbound photo URL to perform server-side request forgery.