Home

Description

OpenClaw versions prior to 2026.2.23 contain a vulnerability in Twilio webhook event deduplication where normalized event IDs are randomized per parse, allowing replay events to bypass manager dedupe checks. Attackers can replay Twilio webhook events to trigger duplicate or stale call-state transitions, potentially causing incorrect call handling and state corruption.

PUBLISHED Reserved 2026-03-10 | Published 2026-03-21 | Updated 2026-03-23 | Assigner VulnCheck




MEDIUM: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

MEDIUM: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Problem types

CWE-294 Authentication Bypass by Capture-replay

Product status

Default status
unaffected

Any version before 2026.2.23
affected

2026.2.23 (semver)
unaffected

Credits

Jisung (@jiseoung) reporter

References

github.com/...enclaw/security/advisories/GHSA-vqx8-9xxw-f2m7 (GitHub Security Advisory (GHSA-vqx8-9xxw-f2m7)) third-party-advisory

github.com/...ommit/1d28da55a5d0ff409e34999e0961157e9db0a2ab (Patch Commit) patch

www.vulncheck.com/...s-via-randomized-event-id-normalization (VulnCheck Advisory: OpenClaw < 2026.2.23 - Twilio Webhook Replay Bypass via Randomized Event ID Normalization) third-party-advisory

cve.org (CVE-2026-32053)

nvd.nist.gov (CVE-2026-32053)

Download JSON