Junglewise Threat Intelligence

OpenClaw Plivo V2 replay protection bypass via query parameter manipulation

Severity: low · CVSS 3.1 · Published 2026-04-10

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a security library that verifies webhook signatures for voice communication platforms like Plivo. A flaw in its Plivo V2 signature verification allowed attackers to bypass replay protection by adding or modifying query parameters on signed requests, essentially creating new valid requests from existing ones. This could allow attackers to replay or forge webhook requests, potentially triggering unintended actions in applications that rely on OpenClaw for webhook security.

Technical details

The vulnerability is a replay protection bypass (CWE-294) in OpenClaw's Plivo V2 webhook signature verification logic. While V2 signature validation correctly canonicalized to the base URL without query parameters, the replay key derivation incorrectly used the full verification URL including query strings. This allowed attackers to create query-only variants of a signed request that would pass verification as a new, fresh request rather than being flagged as a replay. The attack requires network access to send HTTP requests but no authentication or user interaction. An attacker could exploit this to replay or forge authenticated webhook requests. The fix, released in v2026.3.23, ensures the replay key is derived from only the base URL without query parameters.

Affected products

  • OpenClaw OpenClaw < 2026.3.23

Timeline

  • 2026-03-24: disclosed: Advisory GHSA-cg6c-q2hx-69h7 published
  • 2026-03-23: patched: Fix released in v2026.3.23
  • 2026-04-10: other: Duplicate advisory GHSA-j56c-wpqm-h24x withdrawn

References

Related threats