Junglewise Threat Intelligence

OpenClaw webhook secret revocation bypass in Slack and Zalo integrations

Severity: low · CVSS 3.1 · Published 2026-06-13

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a popular workflow automation and integration platform used to connect applications like Slack and Zalo via webhooks. A vulnerability allows old webhook secrets to remain active briefly after an operator rotates or revokes them, potentially allowing attackers with stale credentials to continue delivering events to the system. This could lead to unauthorized data ingestion or actions within integrated workflows until the secrets are fully deactivated.

Technical details

This is a credential revocation bypass vulnerability (CWE-613) affecting OpenClaw's webhook secret management. When the secrets.reload function is called to revoke old Slack and Zalo webhook secrets, the secrets may remain active for a brief window, allowing callers with previously-issued credentials to continue authenticating. The vulnerability is triggered when the affected feature is enabled and reachable by lower-trust inputs. An attacker who obtained a webhook secret before rotation could exploit the stale-secret window to deliver additional webhook events after the operator believed the credential was revoked. The issue is patched in OpenClaw version 2026.4.22 and later. Mitigation includes restarting the affected channel runtime after rotating secrets and disabling the feature when not in use.

Affected products

  • OpenClaw OpenClaw <2026.4.22

Timeline

  • 2026-05-28: disclosed
  • 2026-06-13: advisory: GHSA-p68j-q8j9-jwf5 published as duplicate of GHSA-275c-xpvc-jgfw
  • 2026-04-22: patched: Version 2026.4.22 released with fix
  • 2026-08-24: other: GHSA-p68j-q8j9-jwf5 withdrawn as duplicate

References

Related threats