Junglewise Threat Intelligence

CVE-2026-41402: OpenClaw webhook replay cache cross-target scope bypass

CVE-2026-41402 · Severity: low · CVSS 3.1 · Published 2026-04-02

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a JavaScript library that handles Zalo webhook integrations for messaging applications. A flaw in its webhook replay detection cache allows authenticated attackers with access to sibling targets to bypass message deduplication, potentially replaying messages across unintended targets and causing duplicate message delivery or data inconsistency.

Technical details

The vulnerability is a scope bypass in the webhook replay deduplication cache mechanism, which uses message IDs that are keyed too broadly across multiple target contexts. An authenticated attacker with access to sibling targets can craft requests to the Zalo webhook endpoint that reuse message IDs from one target to another, bypassing the replay cache intended to prevent duplicate message processing. The issue is classified as CWE-294 (Improper Authentication) and CWE-706 (Use of Incorrectly-Resolved Name or Reference), and requires authenticated access to sibling targets. The fix, released in version 2026.3.31, properly scopes the replay cache deduplication key to prevent cross-target message ID collisions.

Affected products

  • OpenClaw openclaw <=2026.3.28

Timeline

  • 2026-04-02: disclosed
  • 2026-03-31: patched: Fix commit 4d038bb; patched version 2026.3.31 released
  • 2026-04-28: advisory: CVE-2026-41402 published

References

Related threats