Executive brief
OpenClaw is an open-source tool used for managing bot integrations. A security flaw in its QQBot component allows attackers to bypass safety checks and force the server to make unintended web requests. This could be used to probe internal network services or relay unauthorized traffic, potentially exposing sensitive internal information.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in OpenClaw's QQBot integration prior to version 2026.4.20. The vulnerability is located in the direct-upload media path, specifically within the 'uploadC2CMedia' and 'uploadGroupMedia' endpoints. While the local download path implemented SSRF protections, the direct-upload path skipped these validations. An unauthenticated remote attacker can provide crafted image URLs to these endpoints, causing the server to initiate requests to arbitrary internal or external destinations. This can be used to relay unintended requests or perform internal network scanning. The issue is fixed in version 2026.4.20 by applying the SSRF guard to the affected URL paths.
Affected products
- openclaw openclaw < 2026.4.20
Timeline
- 2026-04-21: patched: Fix committed in version 2026.4.20
- 2026-05-06: disclosed: Initial advisory published
- 2026-05-11: advisory: Advisory withdrawn as duplicate of GHSA-c4qg-j8jg-42q5