PT-2026-23540 · Unknown · Openclaw Voice-Call Plugin+2

0X5T

·

Published

2026-02-17

·

Updated

2026-03-07

·

CVE-2026-28465

CVSS v4.0

8.2

High

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw voice-call plugin versions prior to 2026.2.3 @clawdbot/voice-call versions through 2026.1.24
Description The voice-call plugin contains a flaw in webhook verification that allows remote attackers to bypass authentication by providing untrusted forwarded headers. Specifically, the issue arises when deployments implicitly trust forwarded headers such as Forwarded or X-Forwarded-*, enabling attackers to manipulate these headers and spoof webhook events. This can occur in reverse-proxy configurations where these headers are not overwritten by a trusted proxy. The root cause is the acceptance of untrusted forwarded headers during webhook verification.
Recommendations Versions prior to 2026.2.3 should be upgraded to version 2026.2.3 or later. Versions through 2026.1.24 should be migrated to the @openclaw/voice-call package and upgraded to version 2026.2.3 or later. If an immediate upgrade is not possible, remove Forwarded and X-Forwarded-* headers at the network edge to prevent clients from directly supplying them.

Fix

Authentication Bypass by Spoofing

Improper Authentication

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

CVE-2026-28465
GHSA-3M3Q-X3GJ-F79X

Affected Products

@Clawdbot/Voice-Call
@Openclaw/Voice-Call
Openclaw Voice-Call Plugin