CVE-2026-45002

OpenClaw before 2026.4.20 contains a hook session-key bypass vulnerability that allows attackers to circumvent the hooks.allowRequestSessionKey opt-in restriction. Attackers can render externally influenced session keys through templated hook mappings to bypass webhook routing isolation controls.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

13 May 2026, 14:13

Type Values Removed Values Added
First Time Openclaw
Openclaw openclaw
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
References () https://github.com/openclaw/openclaw/commit/5275d008ed33203dba3f98e969ad683a65c416c3 - () https://github.com/openclaw/openclaw/commit/5275d008ed33203dba3f98e969ad683a65c416c3 - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-2xcp-x87w-q377 - () https://github.com/openclaw/openclaw/security/advisories/GHSA-2xcp-x87w-q377 - Third Party Advisory
References () https://www.vulncheck.com/advisories/openclaw-hook-session-key-bypass-via-template-mapping - () https://www.vulncheck.com/advisories/openclaw-hook-session-key-bypass-via-template-mapping - Third Party Advisory, Patch

11 May 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-11 18:16

Updated : 2026-05-13 14:13


NVD link : CVE-2026-45002

Mitre link : CVE-2026-45002

CVE.ORG link : CVE-2026-45002


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-863

Incorrect Authorization