OpenClaw before 2026.3.28 contains a webhook replay vulnerability in Plivo V3 signature verification that canonicalizes query ordering for signatures but hashes raw URLs for replay detection. Attackers can reorder query parameters to bypass replay cache detection and trigger duplicate voice-call processing with a captured valid signed webhook.
References
| Link | Resource |
|---|---|
| https://github.com/openclaw/openclaw/security/advisories/GHSA-8689-gm9g-jgr6 | Vendor Advisory |
| https://www.vulncheck.com/advisories/openclaw-webhook-replay-via-query-parameter-reordering-in-plivo-v3 | Third Party Advisory |
Configurations
History
30 Apr 2026, 20:45
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-8689-gm9g-jgr6 - Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-webhook-replay-via-query-parameter-reordering-in-plivo-v3 - Third Party Advisory | |
| First Time |
Openclaw openclaw
Openclaw |
28 Apr 2026, 19:37
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-28 19:37
Updated : 2026-04-30 20:45
NVD link : CVE-2026-41395
Mitre link : CVE-2026-41395
CVE.ORG link : CVE-2026-41395
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-325
Missing Cryptographic Step
