OpenClaw before 2026.4.20 contains a hook session-key bypass vulnerability that allows attackers to circumvent the hooks.allowRequestSessionKey opt-in restriction. Attackers can render externally influenced session keys through templated hook mappings to bypass webhook routing isolation controls.
References
| Link | Resource |
|---|---|
| https://github.com/openclaw/openclaw/commit/5275d008ed33203dba3f98e969ad683a65c416c3 | Patch |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-2xcp-x87w-q377 | Third Party Advisory |
| https://www.vulncheck.com/advisories/openclaw-hook-session-key-bypass-via-template-mapping | Third Party Advisory Patch |
Configurations
History
13 May 2026, 14:13
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Openclaw
Openclaw openclaw |
|
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| References | () https://github.com/openclaw/openclaw/commit/5275d008ed33203dba3f98e969ad683a65c416c3 - Patch | |
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-2xcp-x87w-q377 - Third Party Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-hook-session-key-bypass-via-template-mapping - Third Party Advisory, Patch |
11 May 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-11 18:16
Updated : 2026-05-13 14:13
NVD link : CVE-2026-45002
Mitre link : CVE-2026-45002
CVE.ORG link : CVE-2026-45002
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-863
Incorrect Authorization
