Executive brief
OpenClaw, a tool used for managing webhooks, contains a flaw in how it handles Zalo messaging events across different accounts. In environments where multiple accounts are managed, an attacker who controls one account can intentionally block or suppress legitimate notifications and messages intended for other accounts. This results in a service disruption where important business events or customer communications may never be received by the intended recipient.
Technical details
An improper cache isolation vulnerability (CWE-668) exists in OpenClaw's Zalo webhook replay-dedupe mechanism. The deduplication cache was shared across authenticated webhook targets and keyed too broadly using only event_name and message_id. In multi-account deployments, an attacker who can send authenticated Zalo webhooks to their own path can pre-populate the shared cache with specific IDs. This causes the system to incorrectly identify legitimate incoming events for other accounts as duplicate 'replays,' leading to silent event suppression. The vulnerability was addressed in version 2026.3.31 by scoping the cache keys to specific paths and accounts.
Affected products
- OpenClaw OpenClaw >= 2026.2.19, < 2026.3.31
Timeline
- 2026-03-31: patched: Initial fix released in version 2026.3.31
- 2026-04-02: advisory: GitHub Security Advisory published
- 2026-04-28: disclosed: NVD publication date
References
- https://github.com/openclaw/openclaw/commit/4d038bb242c11f39e45f6a4bde400e5fd42e4ebf
- https://github.com/openclaw/openclaw/commit/7cea7c29705b188b464cc9cdc107c275b94b2a72
- https://github.com/openclaw/openclaw/security/advisories/GHSA-fqrj-m88p-qf3v
- https://www.vulncheck.com/advisories/openclaw-webhook-replay-dedupe-cache-event-suppression-via-shared-authentication