CVE-2026-62216 Details
Description
OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or configured input path could cause the media upload to reach network destinations that should have been blocked by OpenClaw policy (server-side request forgery). The practical impact depends on the operator's configuration and whether lower-trust input can reach that path.
A policy bypass vulnerability has been identified in OpenClaw versions 2026.4.20 prior to 2026.5.28, specifically within the QQBot media upload feature. This vulnerability allows lower-trust callers or configured input paths to bypass OpenClaw's policy, potentially leading to server-side request forgery (SSRF) by allowing media uploads to reach network destinations that should have been blocked. The actual impact of this vulnerability varies depending on the operator's configuration and the ability of lower-trust input to access the vulnerable path.
Users are advised to upgrade to OpenClaw version 2026.5.28 or later. Before upgrading, it is recommended to restrict the affected feature to trusted operators or disable it when not needed. As a general hardening measure, keep channel and tool allowlists narrow, avoid sharing one Gateway between mutually untrusted users, and disable the affected feature when it is not needed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/openclaw/openclaw/security/advisories/GHSA-fwgr-fpv9-vf5x | [email protected] | Vendor Advisory |
| https://www.vulncheck.com/advisories/openclaw-policy-bypass-via-media-upload | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openclaw openclaw | >= 2026.4.20, < 2026.5.28 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Modified | CISA-ADP |
| Jul 21, 2026 | Initial Analysis | [email protected] |
| Jul 17, 2026 | New CVE Received | [email protected] |