CVE-2026-44117

OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in QQBot direct media upload that skips URL validation. Attackers can bypass SSRF protections by sending crafted image URLs to uploadC2CMedia and uploadGroupMedia endpoints to relay unintended requests.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-05-06 20:16

Updated : 2026-06-17 10:50


NVD link : CVE-2026-44117

Mitre link : CVE-2026-44117

CVE.ORG link : CVE-2026-44117


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-918

Server-Side Request Forgery (SSRF)