#VU125219 Insufficient verification of data authenticity in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to trigger duplicate voice-call processing.
The vulnerability exists due to improper canonicalization in extensions/voice-call/src/webhook-security.ts when verifying and replay-checking Plivo V3 webhooks. A remote attacker can reorder query parameters in a captured valid signed webhook URL to trigger duplicate voice-call processing.
Exploitation requires capture of one valid signed Plivo V3 webhook.