This advisory has been withdrawn because it is a duplicate of GHSA-5mx2-2mgw-x8rm. This link is maintained to preserve external references.
OpenClaw versions prior to 2026.2.21 BlueBubbles webhook handler contains a passwordless fallback authentication path that allows unauthenticated webhook events in certain reverse-proxy or local routing configurations. Attackers can bypass webhook authentication by exploiting the loopback/proxy heuristics to send unauthenticated webhook events to the BlueBubbles plugin.
{
"github_reviewed": true,
"github_reviewed_at": "2026-03-24T19:07:34Z",
"cwe_ids": [
"CWE-306"
],
"severity": "MODERATE",
"nvd_published_at": "2026-03-21T01:17:10Z"
}