{"id":"CVE-2026-28451","aliases":["GHSA-x22m-j5qq-j49m"],"url":"https://o3.security/vulnerability/CVE-2026-28451","summary":"OpenClaw < 2026.2.14 - SSRF via Feishu Extension Media Fetching","details":"### Summary\nThe Feishu extension could fetch attacker-controlled remote URLs in two paths without SSRF protections:\n\n- `sendMediaFeishu(mediaUrl)`\n- Feishu DocX markdown image URLs (write/append -> image processing)\n\n### Affected versions\n- `< 2026.2.14`\n\n### Patched versions\n- `>= 2026.2.14`\n\n### Impact\nIf an attacker can influence tool calls (directly or via prompt injection), they may be able to trigger requests to internal services and re-upload the response as Feishu media.\n\n### Remediation\nUpgrade to OpenClaw `2026.2.14` or newer.\n\n### Notes\nThe fix routes Feishu remote media fetching through hardened runtime helpers that enforce SSRF policies and size limits.","published":"2026-03-05T21:59:28.780Z","modified":"2026-08-12T03:51:36.821220791Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"openclaw","fixedVersion":"2026.2.14"}],"fix":{"url":"https://github.com/openclaw/openclaw/commit/5b4121d6011a48c71e747e3c18197f180b872c5d","label":"openclaw/openclaw@5b4121d"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28451.json"},{"type":"ADVISORY","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-x22m-j5qq-j49m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28451"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/openclaw-ssrf-via-feishu-extension-media-fetching"},{"type":"FIX","url":"https://github.com/openclaw/openclaw/commit/5b4121d6011a48c71e747e3c18197f180b872c5d"},{"type":"WEB","url":"https://github.com/openclaw/openclaw/pull/16285"},{"type":"PACKAGE","url":"https://github.com/openclaw/openclaw"},{"type":"WEB","url":"https://github.com/openclaw/openclaw/releases/tag/v2026.2.14"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:36.821220791Z"}}