Vulnerability Description
OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in QQBot direct media upload that skips URL validation. Attackers can bypass SSRF protections by sending crafted image URLs to uploadC2CMedia and uploadGroupMedia endpoints to relay unintended requests.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openclaw | Openclaw | < 2026.4.20 |
Related Weaknesses (CWE)
References
- https://github.com/openclaw/openclaw/commit/49db424c8001f2f419aad85f434894d8d85cPatch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-c4qg-j8jg-42q5MitigationVendor Advisory
- https://www.vulncheck.com/advisories/openclaw-server-side-request-forgery-in-qqbThird Party Advisory
FAQ
What is CVE-2026-44117?
CVE-2026-44117 is a vulnerability with a CVSS score of 5.8 (MEDIUM). OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in QQBot direct media upload that skips URL validation. Attackers can bypass SSRF protections by sending crafted image UR...
How severe is CVE-2026-44117?
CVE-2026-44117 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-44117?
Check the references section above for vendor advisories and patch information. Affected products include: Openclaw Openclaw.