Impact
OpenClaw 2026.4.20 and earlier releases of the OpenClaw application contain a Server‑Side Request Forgery flaw (CWE‑918) in the QQBot media upload component. The bug allows a caller with lower trust or an attacker who can influence the configured input path to cause the application to download content from arbitrary network destinations that the policy should block. While the ability to exfiltrate data or use the server as an internal proxy is limited to the operator’s configuration, the flaw undermines intended isolation and could expose sensitive internal resources.
Affected Systems
The affected stack is the OpenClaw Node.js implementation of the QQBot media upload feature, running versions prior to 2026.5.28. Operators using the 2026.4.20 release or any earlier build are susceptible unless a previous patch has been applied.
Risk and Exploitability
The CVSS score of 2.3 signals a relatively low impact, and the EPSS score of less than 1 % indicates a very low probability of exploitation. Because the vulnerability is not listed in CISA’s KEV catalog, it is not a widely publicized threat. The attack requires reaching the media upload endpoint as a lower‑trust caller or manipulating the input path; successful exploitation is therefore contingent on the operator’s trust and path validation settings, which makes the overall risk typically low but potentially higher if policy enforcement is lax.
OpenCVE Enrichment