Junglewise Threat Intelligence

OpenClaw Google Chat webhook authentication bypass

Severity: low · CVSS 3.1 · Published 2026-04-10

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a JavaScript library that integrates with Google Chat to handle webhook communications. The vulnerability allows attackers to bypass webhook authentication by submitting non-deployment add-on principals, enabling unauthorized actions through the Google Chat integration without proper authorization.

Technical details

This is an improper authentication verification vulnerability (CWE-290) in OpenClaw's Google Chat app-url webhook handling. The vulnerable code in extensions/googlechat/src/auth.ts failed to properly validate that incoming add-on principals matched the expected deployment binding. Attackers can exploit this by providing non-deployment add-on principals to bypass webhook authentication checks. The fix, released in version 2026.3.22, requires expectedAddOnPrincipal matching and rejects unexpected issuers. Attack vector is network-based and requires the attacker to have knowledge of the webhook endpoint.

Affected products

  • OpenClaw openclaw < 2026.3.22

Timeline

  • 2026-03-24: disclosed
  • 2026-03-22: patched: Fix released in version 2026.3.22
  • 2026-04-10: advisory: GHSA-hgwr-wr8h-rxm7 published (later withdrawn as duplicate of GHSA-mp66-rf4f-mhh8)
  • 2026-04-18: other: Advisory GHSA-hgwr-wr8h-rxm7 withdrawn as duplicate

References

Related threats