GHSA-fqrj-m88p-qf3v

Suggest an improvement
Source
https://github.com/advisories/GHSA-fqrj-m88p-qf3v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-fqrj-m88p-qf3v/GHSA-fqrj-m88p-qf3v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-fqrj-m88p-qf3v
Aliases
Downstream
Published
2026-04-07T18:14:50Z
Modified
2026-07-08T08:12:54Z
Severity
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenClaw: Zalo replay dedupe cache could suppress events across authenticated webhook targets
Details

Summary

Before OpenClaw 2026.3.31, the Zalo webhook replay-dedupe cache was shared across authenticated webhook targets and keyed too broadly. In multi-account deployments, a replay seen on one account could suppress a legitimate event on another account if event_name and message_id matched.

Impact

An attacker who controlled one authenticated Zalo webhook path in a multi-account gateway deployment could cause silent message suppression on a different Zalo account sharing that gateway. This was an availability issue; it did not provide cross-account authentication or data access.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Affected versions: >= 2026.2.19, < 2026.3.31
  • Patched versions: >= 2026.3.31
  • Latest published npm version: 2026.4.1

Fix Commit(s)

  • 4d038bb242c11f39e45f6a4bde400e5fd42e4ebf — scope webhook replay dedupe per target
  • 7cea7c29705b188b464cc9cdc107c275b94b2a72 — follow-up hardening to scope replay dedupe by path and account

Release Process Note

The initial fix shipped in OpenClaw 2026.3.31 on March 31, 2026. The current published npm release 2026.4.1 from April 1, 2026 also contains follow-up hardening for the same surface.

Thanks @nexrin for reporting.

Database specific
{
    "cwe_ids":  [
        "CWE-287"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-04-07T18:14:50Z",
    "nvd_published_at":  null,
    "severity":  "LOW"
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
2026.2.19
Fixed
2026.3.31

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-fqrj-m88p-qf3v/GHSA-fqrj-m88p-qf3v.json"