Server-Side Request Forgery Vulnerability in OpenClaw Zalo Plugin
CVE-2026-44116

6.9MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
6 May 2026

What is CVE-2026-44116?

The Zalo plugin in OpenClaw versions prior to 2026.4.22 is affected by a server-side request forgery (SSRF) vulnerability. This issue arises in the plugin's sendPhoto function, which inadequately validates outbound photo URLs. Attackers can exploit this flaw by supplying malicious URLs to the Zalo Bot API, thereby bypassing the existing SSRF protection and potentially gaining unauthorized access to sensitive internal resources.

Affected Version(s)

OpenClaw 0 < 2026.4.22

OpenClaw 2026.4.22

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

foodlook
.