CVE-2026-41914
8.5OpenClaw · OpenClaw
OpenClaw contains a server-side request forgery vulnerability in QQ Bot media download paths that allows authenticated attackers to access internal network resources.
Executive summary
A server-side request forgery vulnerability in OpenClaw allows authenticated attackers to bypass security protections and access sensitive internal network resources.
Vulnerability
This vulnerability is a Server-Side Request Forgery (CWE-918) flaw located in the QQ Bot media download component. Based on the CVSS vector, the flaw requires low privileges (authenticated) to trigger.
Business impact
Successful exploitation of this vulnerability permits an attacker to perform internal network reconnaissance or interact with services restricted to the internal network. Given the CVSS score of 8.5, this high-severity flaw poses a significant risk to organizational confidentiality by enabling unauthorized access to internal systems that are otherwise shielded from the public internet.
Remediation
Immediate Action: Update the OpenClaw package to version 2026.4.8 or later to incorporate the vendor-provided patch.
Proactive Monitoring: Monitor application access logs for suspicious requests directed at internal-only endpoints or unusual outbound traffic originating from the OpenClaw service.
Compensating Controls: Implement strict egress filtering on the server hosting OpenClaw to prevent the service from initiating unauthorized connections to sensitive internal subnets.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations utilizing OpenClaw must prioritize updating to version 2026.4.8 immediately. Because the vulnerability allows an authenticated attacker to pivot into the internal network, failing to patch this flaw leaves the environment susceptible to internal data exposure and potential escalation of privileges.
More OpenClaw CVEs
Sources
Originally found and disclosed by Adithyan AK (@adithyan-ak), per the CVE Program record.
- GitHub Security Advisory (GHSA-3fv3-6p2v-gxwj) Vendor advisory
- Patch Commit Patch commit
- VulnCheck Advisory: OpenClaw < 2026.4.8 - Server-Side Request Forgery in QQ Bot Media Fetch Paths Third-party advisory