Executive brief
OpenClaw is an integration tool used to connect Nextcloud Talk with external systems via webhooks. A flaw in webhook request validation allows attackers to capture and replay valid signed webhook requests, causing duplicate message processing. This can result in duplicate messages, unwanted duplicate actions, or service disruption for teams using this integration.
Technical details
OpenClaw's Nextcloud Talk webhook handler verifies HMAC signatures on incoming webhook requests but lacked persistent replay detection state. While individual HMAC verification was performed, the absence of durable per-event deduplication allowed a captured, validly-signed webhook request to be replayed after the initial replay-window expired or following a process restart. The vulnerability is a capture-replay flaw (CWE-294) where the attacker needs network access to capture a valid webhook and the ability to retransmit it. The fix adds persistent per-account replay deduplication, pre-side-effect replay validation, and backend-origin verification. Patched in version 2026.2.25.
Affected products
- OpenClaw openclaw <= 2026.2.24
Timeline
- 2026-03-03: disclosed
- 2026-02-26: patched: Fix released in version 2026.2.25