PT-2026-34768 · Plivo · Openclaw
Keensecuritylab
·
Published
2026-04-02
·
Updated
2026-04-25
·
CVE-2026-41337
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.31
Description
A callback origin mutation issue exists in Plivo voice-call replay. This allows attackers who have captured valid callbacks for live calls to mutate the in-process callback origin before the replay is rejected, enabling the manipulation of callback origins during the replay process.
Recommendations
Update to version 2026.3.31.
Fix
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw