Junglewise Threat Intelligence

CVE-2026-44117: OpenClaw QQBot direct media upload SSRF validation bypass

CVE-2026-44117 · Severity: low · CVSS 3.1 · Published 2026-04-25

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a JavaScript library that enables QQ Bot integration for media handling and messaging. The vulnerability allows attackers to bypass security checks when uploading media directly, potentially forcing the bot to make requests to internal services or unintended external URLs that the operator did not authorize. This could lead to information disclosure through request relay if those services expose sensitive data in responses.

Technical details

The vulnerability is a Server-Side Request Forgery (SSRF) in the QQBot direct media upload path (CWE-918). The affected functions uploadC2CMedia and uploadGroupMedia did not validate image URLs provided by attackers before forwarding them, unlike the local download path which applied SSRF validation checks. An unauthenticated remote attacker can supply a crafted URL that causes the QQBot service to make HTTP requests to internal or operator-unintended destinations. The impact is limited to QQBot outbound media handling and does not directly expose arbitrary local files. The fix, released in version 2026.4.20, adds URL validation before processing direct-upload media requests (commit 49db424c8001f2f419aad85f434894d8d85c1a09).

Affected products

  • OpenClaw OpenClaw < 2026.4.20

Timeline

  • 2026-04-25: disclosed
  • 2026-04-20: patched: version 2026.4.20

References

Related threats