Skip to content
CVSS 8.5 · HIGH

CVE-2026-41914

OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in QQ Bot media download paths that bypass SSRF protection. Attackers can exploit unprotected media fetch endpoints to access internal resources and bypass allowlist policies.

View on NVD

Analysis

OpenClaw is a niche engine or bot framework primarily associated with the QQ messenger ecosystem, which has virtually no footprint in the Mexican developer community. While the SSRF vulnerability is significant for users of the tool, the software is not part of the standard stack for our members.

Severity

Score: 8.5(HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
AV: NETWORK
AC: LOW
PR: LOW
UI: NONE
S: CHANGED
C: HIGH
I: LOW
A: NONE
Weakness (CWE): CWE-918

EPSS

Probability of exploitation (next 30 days): 0.0003 (0.0%)
Percentile: 9.0%
EPSS: 2026-05-06

Affects

openclaw:openclaw

Technical description

OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in QQ Bot media download paths that bypass SSRF protection. Attackers can exploit unprotected media fetch endpoints to access internal resources and bypass allowlist policies.

Published: 4/28/2026, 7:37:45 PM
Last modified: 4/30/2026, 2:02:57 PM

References

HomeEventsBlogResourcesTeam