highVulnerability
GHSA-8689-gm9g-jgr6
## Summary Plivo V3 signature verification canonicalized query ordering, but replay detection hashed the raw verification URL. Reordering query parameters preserved a valid signature while producing a fresh replay-cache key. ## Impact An attacker who captured one valid signed Plivo V3 webhook could replay the same event by permuting query parameters and trigger duplicate voice-call processing. ## Affected Component `extensions/voice-call/src/webhook-security.ts` ## Fixed Versions - Affected: `<= 2026.3.24` - Patched: `>= 2026.3.28` - Latest stable `2026.3.28` contains the fix. ## Fix Fixed by commit `85777e726c` (`Voice Call: canonicalize Plivo V3 replay key`).
Properties
- ghsa_id
- GHSA-8689-gm9g-jgr6
- summary
- OpenClaw: Voice-call Plivo V3 webhook replay key uses unsorted URL, allowing replay via query-parameter reordering
- severity
- high
- cve_id
- GHSA-8689-gm9g-jgr6
- is_ghsa_only
- true
- ghsa_published
- 2026-03-31T23:50:02Z
- source_url
- https://github.com/advisories/GHSA-8689-gm9g-jgr6
- ghsa_updated
- 2026-03-31T23:50:04Z
Related Entities (3)
AFFECTS (1)
→[Software]npm/OpenClaw
REPORTED_BY (1)
→[Source]GitHub Advisory Database
HAS_WEAKNESS (1)
→[Weakness]Authentication Bypass by Capture-replay
Explore deeper with Ninja Signal's threat intelligence graph