HIGH 8.6 npm
Duplicate Advisory: OpenClaw validates Zalo outbound photo URLs through the SSRF guard
GHSA-qvmw-h675-h7qg
Published ยท Modified
Description
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-2hh7-c75g-qj2r. This link is maintained to preserve external references.
Original Description
OpenClaw before 2026.4.22 contains a server-side request forgery vulnerability in the Zalo plugin's sendPhoto function that fails to validate outbound photo URLs through the SSRF guard. Attackers can bypass SSRF protection by providing malicious photo URLs to the Zalo Bot API, enabling unauthorized access to internal resources.
References
- WEB https://github.com/openclaw/openclaw/security/advisories/GHSA-2hh7-c75g-qj2r
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-44116
- WEB https://github.com/openclaw/openclaw/commit/a65eb1b864b7630c1242a82de9e5799b80583c3f
- WEB https://www.vulncheck.com/advisories/openclaw-server-side-request-forgery-in-zalo-photo-url-validation
Ready to move
Start Securing
Free, no credit card | First findings in minutes