Junglewise Threat Intelligence

CVE-2026-62216: OpenClaw SSRF in QQBot media upload feature

CVE-2026-62216 · Severity: medium · CVSS 5 · Published 2026-07-17

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a gateway and bot integration platform, contains a security flaw in its QQBot media upload feature. An attacker with low-level access could bypass internal security policies to force the server to connect to unauthorized network destinations. This could allow an attacker to probe internal network services or access sensitive data that should be restricted by the system's security rules.

Technical details

A server-side request forgery (SSRF) vulnerability exists in the QQBot media upload component of OpenClaw. The issue stems from a policy bypass where a lower-trust caller or a specifically configured input path can trigger media uploads to network destinations that are explicitly blocked by OpenClaw's security policies. An authenticated attacker with low privileges can exploit this over the network to reach internal or restricted URLs. The vulnerability is patched in version 2026.5.28. Operators are advised to upgrade or restrict access to the affected feature until a patch is applied.

Affected products

  • OpenClaw OpenClaw >= 2026.4.20, < 2026.5.28

Timeline

  • 2026-06-30: advisory: GitHub Security Advisory published
  • 2026-07-16: disclosed: NVD and VulnCheck publication date

References

Related threats