Description
OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or configured input path could cause the media upload to reach network destinations that should have been blocked by OpenClaw policy (server-side request forgery). The practical impact depends on the operator's configuration and whether lower-trust input can reach that path.
Published: 2026-07-17
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OpenClaw 2026.4.20 and earlier releases of the OpenClaw application contain a Server‑Side Request Forgery flaw (CWE‑918) in the QQBot media upload component. The bug allows a caller with lower trust or an attacker who can influence the configured input path to cause the application to download content from arbitrary network destinations that the policy should block. While the ability to exfiltrate data or use the server as an internal proxy is limited to the operator’s configuration, the flaw undermines intended isolation and could expose sensitive internal resources.

Affected Systems

The affected stack is the OpenClaw Node.js implementation of the QQBot media upload feature, running versions prior to 2026.5.28. Operators using the 2026.4.20 release or any earlier build are susceptible unless a previous patch has been applied.

Risk and Exploitability

The CVSS score of 2.3 signals a relatively low impact, and the EPSS score of less than 1 % indicates a very low probability of exploitation. Because the vulnerability is not listed in CISA’s KEV catalog, it is not a widely publicized threat. The attack requires reaching the media upload endpoint as a lower‑trust caller or manipulating the input path; successful exploitation is therefore contingent on the operator’s trust and path validation settings, which makes the overall risk typically low but potentially higher if policy enforcement is lax.

Generated by OpenCVE AI on July 31, 2026 at 00:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to OpenClaw version 2026.5.28 or later
  • Limit the media upload endpoint to callers that meet the trusted caller criteria and tighten validation of the input path
  • Enforce the server‑side request policy to block unintended internal destinations and monitor logs for unauthorized requests

Generated by OpenCVE AI on July 31, 2026 at 00:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Description OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or configured input path could cause the media upload to reach network destinations that should have been blocked by OpenClaw policy (server-side request forgery). The practical impact depends on the operator's configuration and whether lower-trust input can reach that path.
Title OpenClaw 2026.4.20 < 2026.5.28 Policy Bypass via Media Upload
First Time appeared Openclaw
Openclaw openclaw
Weaknesses CWE-918
CPEs cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Vendors & Products Openclaw
Openclaw openclaw
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N'}


Subscriptions

Openclaw Openclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-23T19:26:02.159Z

Reserved: 2026-07-13T16:39:44.419Z

Link: CVE-2026-62216

cve-icon Vulnrichment

Updated: 2026-07-23T19:25:55.892Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:00:14Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)