mediumCVSS 4.8Vulnerability

GHSA-59xc-5v89-r7pr

### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-mf5g-6r6f-ghhm. This link is maintained to preserve external references. ### Original Description OpenClaw before 2026.3.25 contains a pre-authentication rate-limit bypass vulnerability in webhook token validation that allows attackers to brute-force weak webhook secrets. The vulnerability exists because invalid webhook tokens are rejected without throttling repeated authentication attempts, enabling attackers to guess weak tokens through rapid successive requests.

Properties

ghsa_id
GHSA-59xc-5v89-r7pr
severity
medium
summary
Duplicate Advisory: OpenClaw: Synology Chat Webhook Pre-Auth Rate-Limit Bypass Enables Brute-Force Guessing of Webhook Token
cvss_score
4.8
cve_id
GHSA-59xc-5v89-r7pr
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
is_ghsa_only
true
ghsa_published
2026-04-10T00:30:30Z
source_url
https://github.com/advisories/GHSA-59xc-5v89-r7pr
ghsa_updated
2026-04-10T20:25:03Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]npm/OpenClaw

AFFECTS (1)

[Software]npm/OpenClaw

REPORTED_BY (1)

[Source]GitHub Advisory Database

HAS_WEAKNESS (1)

[Weakness]Improper Restriction of Excessive Authentication Attempts

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-59xc-5v89-r7pr (CVSS 4.8) — Ninja Signal Threat Intelligence | Ninja Signal