CVE-2026-44117 | OpenClaw up to 2026.4.19 uploadC2CMedia/uploadGroupMedia server-side request forgery (GHSA-c4qg-j8jg-42q5)
A vulnerability was found in OpenClaw up to 2026.4.19. It has been declared as critical. Affected by this issue is the function uploadC2CMedia/uploadGroupMedia. Executing a manipulation can lead to server-side request forgery.
This vulnerability is registered as CVE-2026-44117. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.