---
id: CVE-2026-44116
title: >-
  OpenClaw < 2026.4.22 - Server-Side Request Forgery in Zalo Photo URL
  Validation
summary: >-
  OpenClaw before 2026.4.22 contains a server-side request forgery vulnerability
  in the Zalo plugin's sendPhoto function that fails to validate outbound photo
  URLs through the SSRF guard. Attackers can bypass SSRF protection by providing
  m…
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'
cvssSource: cna
cwe:
  - CWE-918
vendor: OpenClaw
product: OpenClaw
affected:
  - OpenClaw < 2026.4.22
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-05-07T13:59:02.602216Z'
published: '2026-05-06'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T14:17:43.147Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-44116'
references:
  - url: >-
      https://github.com/openclaw/openclaw/security/advisories/GHSA-2hh7-c75g-qj2r
    label: GitHub Security Advisory (GHSA-2hh7-c75g-qj2r)
  - url: >-
      https://github.com/openclaw/openclaw/commit/a65eb1b864b7630c1242a82de9e5799b80583c3f
    label: Patch Commit
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-server-side-request-forgery-in-zalo-photo-url-validation
    label: >-
      VulnCheck Advisory: OpenClaw < 2026.4.22 - Server-Side Request Forgery in
      Zalo Photo URL Validation
tags:
  - cve.org
epss: 0.00475
epssPercentile: 0.38478
ingestedAt: '2026-09-24T15:45:56.729Z'
---

## Overview

OpenClaw before 2026.4.22 contains a server-side request forgery vulnerability in the Zalo plugin's sendPhoto function that fails to validate outbound photo URLs through the SSRF guard. Attackers can bypass SSRF protection by providing malicious photo URLs to the Zalo Bot API, enabling unauthorized access to internal resources.

## Affected

- `OpenClaw < 2026.4.22`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
