PT-2026-34768 · Plivo · Openclaw

Keensecuritylab

·

Published

2026-04-02

·

Updated

2026-04-25

·

CVE-2026-41337

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.31
Description A callback origin mutation issue exists in Plivo voice-call replay. This allows attackers who have captured valid callbacks for live calls to mutate the in-process callback origin before the replay is rejected, enabling the manipulation of callback origins during the replay process.
Recommendations Update to version 2026.3.31.

Fix

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

CVE-2026-41337
GHSA-89R3-6X4J-V7WF
GHSA-CW28-63X4-37C3

Affected Products

Openclaw