Description
OpenClaw before 2026.3.22 contains a webhook path route replacement vulnerability in the Synology Chat extension that allows attackers to collapse multi-account configurations onto shared webhook paths. Attackers can exploit inherited or duplicate webhook paths to bypass per-account DM access control policies and replace route ownership across accounts.
Problem types
CWE-706: Use of Incorrectly-Resolved Name or Reference
Product status
Any version before 2026.3.22
2026.3.22 (semver)
Credits
tdjackey
References
github.com/...enclaw/security/advisories/GHSA-rqp8-q22p-5j9q (GitHub Security Advisory (GHSA-rqp8-q22p-5j9q))
github.com/...ommit/630f1479c44f78484dfa21bb407cbe6f171dac87 (Patch Commit #1)
github.com/...ommit/980940aa58f862da4e19372597bbc2a9f268d70b (Patch Commit #2)
www.vulncheck.com/...lacement-vulnerability-in-synology-chat (VulnCheck Advisory: OpenClaw < 2026.3.22 - Webhook Path Route Replacement Vulnerability in Synology Chat)