Google Chat app-url webhook verification accepted add-on principals outside the intended deployment binding.
openclaw (npm)v2026.3.23-2 (630f1479c44f78484dfa21bb407cbe6f171dac87)2026.3.23-2a47722de7e3c9cbda8d5512747ca7e3bb8f6ee66The fix shipped in v2026.3.22 and remains present in v2026.3.23 and v2026.3.23-2.
OpenClaw thanks @ijxpwastaken for reporting.
{
"github_reviewed_at": "2026-03-26T21:37:36Z",
"nvd_published_at": null,
"cwe_ids": [
"CWE-290",
"CWE-863"
],
"severity": "MODERATE",
"github_reviewed": true
}