highVulnerability

GHSA-8689-gm9g-jgr6

## Summary Plivo V3 signature verification canonicalized query ordering, but replay detection hashed the raw verification URL. Reordering query parameters preserved a valid signature while producing a fresh replay-cache key. ## Impact An attacker who captured one valid signed Plivo V3 webhook could replay the same event by permuting query parameters and trigger duplicate voice-call processing. ## Affected Component `extensions/voice-call/src/webhook-security.ts` ## Fixed Versions - Affected: `<= 2026.3.24` - Patched: `>= 2026.3.28` - Latest stable `2026.3.28` contains the fix. ## Fix Fixed by commit `85777e726c` (`Voice Call: canonicalize Plivo V3 replay key`).

Properties

ghsa_id
GHSA-8689-gm9g-jgr6
summary
OpenClaw: Voice-call Plivo V3 webhook replay key uses unsorted URL, allowing replay via query-parameter reordering
severity
high
cve_id
GHSA-8689-gm9g-jgr6
is_ghsa_only
true
ghsa_published
2026-03-31T23:50:02Z
source_url
https://github.com/advisories/GHSA-8689-gm9g-jgr6
ghsa_updated
2026-03-31T23:50:04Z

Related Entities (3)

AFFECTS (1)

[Software]npm/OpenClaw

REPORTED_BY (1)

[Source]GitHub Advisory Database

HAS_WEAKNESS (1)

[Weakness]Authentication Bypass by Capture-replay

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-8689-gm9g-jgr6 — Ninja Signal Threat Intelligence | Ninja Signal