Server-Side Request Forgery Vulnerability in OpenClaw Zalo Plugin
CVE-2026-44116
6.9MEDIUM
What is CVE-2026-44116?
The Zalo plugin in OpenClaw versions prior to 2026.4.22 is affected by a server-side request forgery (SSRF) vulnerability. This issue arises in the plugin's sendPhoto function, which inadequately validates outbound photo URLs. Attackers can exploit this flaw by supplying malicious URLs to the Zalo Bot API, thereby bypassing the existing SSRF protection and potentially gaining unauthorized access to sensitive internal resources.
Affected Version(s)
OpenClaw 0 < 2026.4.22
OpenClaw 2026.4.22
