Improper control of a resource through its lifetime in OpenClaw - #VU125242
Published: April 8, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to alter the in-process callback origin.
The vulnerability exists due to improper state management in the Plivo callback origin handling logic when replaying a captured valid callback for a live call. A remote attacker can replay a captured valid callback to alter the in-process callback origin.
Replay rejection occurs only after the callback origin has already been mutated.