Executive brief
OpenClaw's voice-call extension is an optional module used to integrate voice call routing with inbound access controls. This vulnerability allows attackers to bypass the allowlist policy through two methods: calling with a missing/anonymous caller ID, or spoofing a caller number that ends with a legitimate allowlisted number. A successful exploit permits unauthorized callers to reach voice agents and trigger automated responses or tool execution, potentially leading to unauthorized access, data theft, or service disruption.
Technical details
The vulnerability is an authentication bypass (CWE-287) in the voice-call extension's inbound allowlist enforcement logic (extensions/voice-call/src/manager.ts). Two distinct flaws exist: (1) empty or missing caller ID values normalize to an empty string, which the allowlist predicate incorrectly evaluates as allowed, and (2) the allowlist matching uses suffix-based comparison instead of strict equality, so any caller number whose digits end with an allowlisted number (e.g., +99915550001234 ending with 15550001234) passes validation. The attack requires no authentication or user interaction and is exploitable remotely over the network. The fix hardens validation by rejecting calls with missing caller IDs and enforcing strict equality matching. Patch available in version 2026.2.2 and later.
Affected products
- openclaw openclaw <= 2026.2.1
Timeline
- 2026-02-14: disclosed: Security advisory published by steipete
- 2026-02-17: advisory: GHSA-4rj2-gpmh-qq5x published
- 2026-02-03: patched: Fix commit f8dfd034f5d9235c5485f492a9e4ccc114e97fdb merged
- 2026-02-17: other: Patched version 2026.2.2 released
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-4rj2-gpmh-qq5x
- https://github.com/openclaw/openclaw/commit/f8dfd034f5d9235c5485f492a9e4ccc114e97fdb
- https://github.com/openclaw/openclaw
- https://github.com/openclaw/openclaw/releases/tag/v2026.2.2
- https://www.vulncheck.com/advisories/openclaw-inbound-allowlist-policy-bypass-in-voice-call-extension-via-empty-caller-id