
CVE-2026-44116 OpenClaw before 2026.4.22 contains a server-side request forgery vulnerability in the Zalo plugin's sendPhoto function that fails to validate outbound photo URLs thro… https://www.cve.org/CVERecord?id=CVE-2026-44116
Post summary
The text discloses a server‑side request forgery (SSRF) vulnerability in OpenClaw’s Zalo plugin (sendPhoto) affecting versions before 2026.4.22.

