CVE-2026-28451: OpenClaw < 2026.2.14 - SSRF via Feishu Extension Media Fetching
OpenClaw versions prior to 2026.2.14 contain server-side request forgery vulnerabilities in the Feishu extension that allow attackers to fetch attacker-controlled remote URLs without SSRF protections via sendMediaFeishu function and markdown image processing. Attackers can influence tool calls through direct manipulation or prompt injection to trigger requests to internal services and re-upload responses as Feishu media.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28451?
CVE-2026-28451 has a severity rating of 9.3, classified as critical.
What type of vulnerability is CVE-2026-28451?
CVE-2026-28451 is a server-side request forgery (SSRF) vulnerability.
How do I fix CVE-2026-28451?
The recommended fix for CVE-2026-28451 is to update OpenClaw to version 2026.2.14 or later.
What software is affected by CVE-2026-28451?
CVE-2026-28451 affects versions of OpenClaw prior to 2026.2.14.
What functionality is exploited in CVE-2026-28451?
CVE-2026-28451 exploits the Feishu extension's media fetching capabilities through the sendMediaFeishu function.