Junglewise Threat Intelligence

CVE-2026-29606: OpenClaw Twilio webhook signature-verification bypass

CVE-2026-29606 · Severity: low · CVSS 3.1 · Published 2026-02-18

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a Node.js library that provides voice-call integration with Twilio, a cloud communications platform. When a developer enables ngrok loopback compatibility mode (a development tunneling feature), the library incorrectly bypasses Twilio webhook signature verification, allowing attackers to send forged webhook events that could trigger unauthorized actions or flood the endpoint with bogus requests.

Technical details

The vulnerability is a missing authentication control (CWE-306) in the Twilio voice-call webhook handler. When the configuration option tunnel.allowNgrokFreeTierLoopbackBypass is explicitly enabled, the library bypasses X-Twilio-Signature validation on incoming webhook requests. The attack vector is network-based and requires no authentication or user interaction; an attacker must discover the public ngrok URL (typically exposed during development). Exploitation allows an unauthenticated attacker to submit forged webhook events, resulting in integrity compromise and potential denial of service via request flooding. The fix (version 2026.2.14 and later) disables signature bypassing and instead reconstructs the public ngrok URL for proper validation.

Affected products

  • OpenClaw openclaw <=2026.2.13

Timeline

  • 2026-02-15: disclosed
  • 2026-02-18: patched

References

Related threats