Executive brief
OpenClaw is a popular open-source bot framework that includes a Zalo messaging plugin. The plugin's photo-sharing feature failed to properly validate outbound URLs against OpenClaw's security controls, allowing attackers to bypass protections and send requests to unauthorized internal systems. This could enable unauthorized access to sensitive internal resources or services.
Technical details
OpenClaw versions up to 2026.4.21 contain a server-side request forgery (SSRF) vulnerability in the Zalo plugin's sendPhoto function. The vulnerable code failed to validate outbound photo URLs through OpenClaw's SSRF guard before forwarding them to the Zalo Bot API. An attacker can supply malicious photo URLs to the API to bypass the SSRF protection mechanism, potentially accessing internal resources not intended to be exposed. The vulnerability requires network access to the API endpoint but no authentication. The fix, released in version 2026.4.22, implements proper URL parsing and validation using the shared SSRF hostname policy before posting to Zalo.
Affected products
- OpenClaw OpenClaw <=2026.4.21
Timeline
- 2026-04-23: disclosed
- 2026-04-23: patched: Version 2026.4.22 released with fix
- 2026-05-06: advisory
- 2026-05-11: other: Advisory withdrawn as duplicate of GHSA-2hh7-c75g-qj2r