CVE-2026-45005

OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to remain valid after rotation and reload. Attackers with previously valid webhook route secrets can continue authenticating requests and invoking configured webhook task flows until gateway or plugin restart.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

13 May 2026, 14:14

Type Values Removed Values Added
First Time Openclaw
Openclaw openclaw
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
References () https://github.com/openclaw/openclaw/commit/36c4a372a0ad5dca8bfc0d93f7aab9c2f2de66fa - () https://github.com/openclaw/openclaw/commit/36c4a372a0ad5dca8bfc0d93f7aab9c2f2de66fa - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-q8ff-7ffm-m3r9 - () https://github.com/openclaw/openclaw/security/advisories/GHSA-q8ff-7ffm-m3r9 - Third Party Advisory
References () https://www.vulncheck.com/advisories/openclaw-webhook-route-secret-cache-not-invalidated-after-rotation - () https://www.vulncheck.com/advisories/openclaw-webhook-route-secret-cache-not-invalidated-after-rotation - Third Party Advisory, Patch

11 May 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-11 18:16

Updated : 2026-05-13 14:14


NVD link : CVE-2026-45005

Mitre link : CVE-2026-45005

CVE.ORG link : CVE-2026-45005


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-672

Operation on a Resource after Expiration or Release