Executive brief
OpenClaw is a library that handles voice-call integrations with Twilio webhooks. A flaw in its replay attack detection allowed attackers who possessed a single valid signed webhook request to replay it multiple times by simply modifying an unsigned header, bypassing the system's safeguards against duplicate or replayed events. This could result in duplicate webhook processing and potential service disruption.
Technical details
OpenClaw's voice-call Twilio webhook handler accepted replay/dedupe identity from the unsigned "i-twilio-idempotency-token" header rather than from authenticated request material. An attacker with one valid signed webhook request could mutate only this unsigned header to bypass replay detection and manager deduplication, allowing replayed signed requests to be processed as fresh events. The vulnerability is classified as authentication bypass by capture-replay (CWE-294) combined with insufficient verification of data authenticity (CWE-345). The fix removes unsigned-header trust from the dedupe identity and binds replay/dedupe verification to authenticated request material instead of mutable headers. Patch version 2026.2.26 is available.
Affected products
- OpenClaw openclaw <= 2026.2.25
Timeline
- 2026-03-03: disclosed
- 2026-02-26: patched: Fix committed; patch version 2026.2.26 planned