CVE-2026-41914
OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in QQ Bot media download paths that bypass SSRF protection. Attackers can exploit unprotected media fetch endpoints to access internal resources and bypass allowlist policies.
Ver en NVDAnálisis
OpenClaw is a niche engine or bot framework primarily associated with the QQ messenger ecosystem, which has virtually no footprint in the Mexican developer community. While the SSRF vulnerability is significant for users of the tool, the software is not part of the standard stack for our members.
Severidad
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:NCWE-918EPSS
Afecta
openclaw:openclawDescripción técnica
OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in QQ Bot media download paths that bypass SSRF protection. Attackers can exploit unprotected media fetch endpoints to access internal resources and bypass allowlist policies.