PT-2026-35796 · Openclaw · Openclaw

Adithyan Ak

·

Published

2026-04-28

·

Updated

2026-04-28

·

CVE-2026-41914

CVSS v3.1

8.5

High

AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in QQ Bot media download paths that bypass SSRF protection. Attackers can exploit unprotected media fetch endpoints to access internal resources and bypass allowlist policies.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-41914

Affected Products

Openclaw