Server-Side Request Forgery (SSRF) in OpenClaw - CVE-2026-28451
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information from internal services.
The vulnerability exists due to server-side request forgery (SSRF) in the Feishu extension when fetching attacker-controlled remote URLs through sendMediaFeishu(mediaUrl) or Feishu DocX markdown image processing. A remote attacker can supply a specially crafted URL to disclose sensitive information from internal services.
Exploitation requires the ability to influence tool calls, directly or via prompt injection, and the fetched response may be re-uploaded as Feishu media.