PT-2026-37012 · Openclaw · Openclaw

Yuki Shiroi

·

Published

2026-04-17

·

Updated

2026-05-05

·

CVE-2026-43526

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.4.12
Description An issue exists in the QQBot reply media URL handling that allows server-side request forgery (SSRF), a flaw where a server is tricked into making requests to an unintended location. Attackers can provide malicious media URLs to fetch arbitrary content, and the retrieved bytes are subsequently re-uploaded through the channel.
Recommendations Update to version 2026.4.12 or newer.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-43526
GHSA-2767-2Q9V-9326

Affected Products

Openclaw