CVE-2026-41914
OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in QQ Bot media download paths that bypass SSRF protection. Attackers can exploit unprotected media fetch endpoints to access internal resources and bypass allowlist policies.
View on NVDAnalysis
OpenClaw is a niche engine or bot framework primarily associated with the QQ messenger ecosystem, which has virtually no footprint in the Mexican developer community. While the SSRF vulnerability is significant for users of the tool, the software is not part of the standard stack for our members.
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:NCWE-918EPSS
Affects
openclaw:openclawTechnical description
OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in QQ Bot media download paths that bypass SSRF protection. Attackers can exploit unprotected media fetch endpoints to access internal resources and bypass allowlist policies.