PT-2026-35779 · Openclaw · Openclaw
Keensecuritylab
·
Published
2026-03-31
·
Updated
2026-04-30
·
CVE-2026-41395
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.28
Description
An issue exists in Plivo V3 signature verification where the system canonicalizes query ordering for signatures but hashes raw URLs for replay detection. This allows attackers to reorder query parameters to bypass replay cache detection, enabling the triggering of duplicate voice-call processing using a captured valid signed webhook.
Recommendations
Update to version 2026.3.28.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw