---
id: CVE-2026-44117
title: >-
  OpenClaw < 2026.4.20 - Server-Side Request Forgery in QQBot Direct Media
  Upload
summary: >-
  OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability
  in QQBot direct media upload that skips URL validation. Attackers can bypass
  SSRF protections by sending crafted image URLs to uploadC2CMedia and
  uploadGroupM…
severity: medium
cvss: 5.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'
cvssSource: cna
cwe:
  - CWE-918
vendor: OpenClaw
product: OpenClaw
affected:
  - OpenClaw < 2026.4.20
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-05-07T13:33:16.415532Z'
published: '2026-05-06'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T14:17:44.099Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-44117'
references:
  - url: >-
      https://github.com/openclaw/openclaw/security/advisories/GHSA-c4qg-j8jg-42q5
    label: GitHub Security Advisory (GHSA-c4qg-j8jg-42q5)
  - url: >-
      https://github.com/openclaw/openclaw/commit/49db424c8001f2f419aad85f434894d8d85c1a09
    label: Patch Commit
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-server-side-request-forgery-in-qqbot-direct-media-upload
    label: >-
      VulnCheck Advisory: OpenClaw < 2026.4.20 - Server-Side Request Forgery in
      QQBot Direct Media Upload
tags:
  - cve.org
epss: 0.00401
epssPercentile: 0.31585
ingestedAt: '2026-09-24T15:45:56.730Z'
---

## Overview

OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in QQBot direct media upload that skips URL validation. Attackers can bypass SSRF protections by sending crafted image URLs to uploadC2CMedia and uploadGroupMedia endpoints to relay unintended requests.

## Affected

- `OpenClaw < 2026.4.20`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
