Loading...
Skip to main content

CVE-2026-44116

MEDIUM

OpenClaw validates Zalo outbound photo URLs through the SSRF guard

Published May 4, 2026Updated May 12, 2026Source: osv

Summary

## Summary Zalo outbound photo URLs are validated through the SSRF guard. ## Affected Packages / Versions - Package: openclaw (npm) - Affected versions: <= 2026.4.21 - Fixed version: 2026.4.22 ## Impact The Zalo plugin could forward an attacker-controlled outbound photo URL to the Zalo Bot API without first applying OpenClaw's SSRF validation policy. ## Fix Zalo sendPhoto now parses and validates outbound photo URLs with the shared SSRF hostname policy before posting to Zalo, and media-reply paths route through the guarded outbound media helpers. ## Fix Commit(s) - a65eb1b864b7630c1242a82de9e5799b80583c3f ## Verification - The fix commit is contained in the public v2026.4.22 tag. - openclaw@2026.4.22 is published on npm and the compiled package contains the fix. - Focused regression coverage for this path passed before publication. OpenClaw thanks @foodlook for reporting.

Remediation

Upgrade to the fixed version using your package manager.

npm
Update openclaw to 2026.4.22 or later
npm install openclaw@2026.4.22

After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.

Affected Packages (1)

PackageEcosystemAffectedFixed In
openclaw
npm
All versions2026.4.22

Vulnerability Classification

Common Weakness Enumeration (CWE) identifiers for this vulnerability type.

  • CWE-918
    Server-Side Request Forgery (SSRF)MITRE

CVSS Score Breakdown

What the CVSS (Common Vulnerability Scoring System) 8.6 score means for each attack dimension.

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Frequently Asked Questions

What is CVE-2026-44116?
OpenClaw validates Zalo outbound photo URLs through the SSRF guard This vulnerability has been assigned a severity rating of MEDIUM (CVSS score: 8.6/10).
How do I check if my project is affected by CVE-2026-44116?
CVE-2026-44116 affects openclaw. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2026-44116 and 200,000+ other known vulnerabilities.

Severity & Exploitability

CVSS Score
8.6

High exploitability or significant impact. Prioritize remediation within days.

Also Known As

GHSA-2hh7-c75g-qj2r

Related CVEs

  • CVE-2026-41329
    CRITICAL

    OpenClaw: Heartbeat context inheritance bypasses sandbox via senderIsOwner escalation

  • CVE-2026-32916
    CRITICAL

    OpenClaw: Plugin subagent routes could bypass gateway authorization with synthetic admin scopes

  • CVE-2026-53822
    HIGH

    OpenClaw: Shell wrapper argv could change between approval and execution

  • CVE-2026-33573
    HIGH

    OpenClaw: Gateway `agent` calls could override the workspace boundary

  • CVE-2026-32917
    HIGH

    OpneClaw accepts unsanitized iMessage attachment paths which allowed SCP remote-path command injection

  • CVE-2026-41386
    HIGH

    OpenClaw: Unbound bootstrap setup codes allow privilege escalation during pairing

  • CVE-2026-33577
    MEDIUM

    OpenClaw: node.pair.approve missing callerScopes validation allows low-privilege operator to approve malicious nodes

  • CVE-2026-43566
    MEDIUM

    OpenClaw: Heartbeat owner downgrade missed untrusted webhook wake events

Check if you're affected

Scan your dependencies to see if this vulnerability affects your projects.

Scan Your Dependencies