Junglewise Threat Intelligence

CVE-2026-45002: OpenClaw hook session-key bypass in gateway hook mappings

CVE-2026-45002 · Severity: medium · CVSS 5.3 · Published 2026-05-11

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a platform that routes webhooks through configurable hook mappings with session-key based isolation controls. A flaw in how template-rendered session keys are validated allows attackers to bypass the allowRequestSessionKey opt-in setting, enabling unauthorized webhook routing to isolated sessions. This weakens the intended isolation boundary between webhook callers and the routing infrastructure, though it does not directly compromise the host system.

Technical details

The vulnerability stems from inconsistent handling of session keys in webhook hook mappings. Templated (template-rendered) session key values were treated differently from request-supplied session keys, allowing attackers to inject externally influenced session keys through templates even when hooks.allowRequestSessionKey was disabled. The vulnerability is rooted in the gateway's hook mapping component, where template rendering was not subject to the same authorization checks as direct request parameters. An attacker with network access can craft requests that trigger template rendering of malicious session keys, bypassing the configured routing opt-in policy and weakening webhook isolation. The fix (commit 5275d008ed33203dba3f98e969ad683a65c416c3) enforces the allowRequestSessionKey gate on template-rendered mapping session keys, treating them as externally supplied routing input and requiring the policy checks. Patched in OpenClaw 2026.4.20.

Affected products

  • OpenClaw openclaw < 2026.4.20

Timeline

  • 2026-04-25: disclosed: Vulnerability published as GHSA-2xcp-x87w-q377
  • 2026-04-21: patched: Fix committed (5275d008ed33203dba3f98e969ad683a65c416c3), released in OpenClaw 2026.4.20

References

Related threats