Twilio webhook replay events could bypass voice-call manager dedupe because normalized event IDs were randomized per parse. A replayed event could be treated as new and trigger duplicate or stale call-state transitions.
openclaw (npm)<= 2026.2.22-2>= 2026.2.23The fix preserves provider event IDs through normalization, adds bounded replay dedupe in webhook security validation, and enforces per-call turn-token checks on call-state transitions.
patched_versions is pre-set to the released version (2026.2.23) This advisory now reflects released fix version 2026.2.23.2.23`.
OpenClaw thanks @jiseoung for reporting.
{
"cwe_ids": [
"CWE-294",
"CWE-863"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-03T19:16:09Z",
"nvd_published_at": null,
"severity": "MODERATE"
}