Skip to content
CVSS 8.5 · HIGH

CVE-2026-41914

OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in QQ Bot media download paths that bypass SSRF protection. Attackers can exploit unprotected media fetch endpoints to access internal resources and bypass allowlist policies.

Ver en NVD

Análisis

OpenClaw is a niche engine or bot framework primarily associated with the QQ messenger ecosystem, which has virtually no footprint in the Mexican developer community. While the SSRF vulnerability is significant for users of the tool, the software is not part of the standard stack for our members.

Severidad

Puntaje: 8.5(HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
AV: NETWORK
AC: LOW
PR: LOW
UI: NONE
S: CHANGED
C: HIGH
I: LOW
A: NONE
Tipo de falla (CWE): CWE-918

EPSS

Probabilidad de explotación (próx. 30 días): 0.0003 (0.0%)
Percentil: 9.0%
EPSS: 2026-05-06

Afecta

openclaw:openclaw

Descripción técnica

OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in QQ Bot media download paths that bypass SSRF protection. Attackers can exploit unprotected media fetch endpoints to access internal resources and bypass allowlist policies.

Publicada: 28/4/2026, 19:37:45
Última modificación: 30/4/2026, 14:02:57

Referencias

InicioEventosBlogRecursosEquipo