CVE-2026-28449
MEDIUMOpenClaw < 2026.2.25 - Webhook Replay Attack via Missing Durable Replay Suppression
Title source: cnaDescription
OpenClaw versions prior to 2026.2.25 lack durable replay state for Nextcloud Talk webhook events, allowing valid signed webhook requests to be replayed without suppression. Attackers can capture and replay previously valid signed webhook requests to trigger duplicate inbound message processing and cause integrity or availability issues.
References (3)
Core 3
Core References
Third Party Advisory third-party-advisory
GitHub Security Advisory (GHSA-r9q5-c7qc-p26w)
https://github.com/openclaw/openclaw/security/advisories/GHSA-r9q5-c7qc-p26w
Patch patch
Patch Commit
https://github.com/openclaw/openclaw/commit/d512163d686ad6741783e7119ddb3437f493dbbc
Third Party Advisory third-party-advisory
VulnCheck Advisory: OpenClaw < 2026.2.25 - Webhook Replay Attack via Missing Durable Replay Suppression
https://www.vulncheck.com/advisories/openclaw-webhook-replay-attack-via-missing-durable-replay-suppression
Scores
CVSS v3
6.5
EPSS
0.0027
EPSS Percentile
18.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-294
Status
published
Products (3)
npm/openclaw
0 - 2026.2.25npm
OpenClaw/OpenClaw
< 2026.2.25
openclaw/openclaw
< 2026.2.25
Published
Mar 19, 2026
Tracked Since
Mar 19, 2026