OpenClaw before 2026.4.20 contains a hook session-key bypass vulnerability that allows attackers to circumvent the hooks.allowRequestSessionKey opt-in restriction. Attackers can render externally influenced session keys through templated hook mappings to bypass webhook routing isolation controls.
References
| Link | Resource |
|---|---|
| https://github.com/openclaw/openclaw/commit/5275d008ed33203dba3f98e969ad683a65c416c3 | Patch |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-2xcp-x87w-q377 | Third Party Advisory |
| https://www.vulncheck.com/advisories/openclaw-hook-session-key-bypass-via-template-mapping | Patch Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-05-11 18:16
Updated : 2026-06-17 10:51
NVD link : CVE-2026-45002
Mitre link : CVE-2026-45002
CVE.ORG link : CVE-2026-45002
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-863
Incorrect Authorization
