GHSA-gcj7-r3hg-m7w6
### Summary The voice-call Twilio webhook path accepted replay/dedupe identity from unsigned request metadata (`i-twilio-idempotency-token`), enabling replayed signed requests to bypass replay detection and manager dedupe by mutating only that header. ### Affected Packages / Versions - Package: `openclaw` (npm) - Affected versions: `<= 2026.2.25` (latest published npm version at triage time) - Fixed on `main`: commit `1aadf26f9acc399affabd859937a09468a9c5cb4` - Planned patched npm version: `2026.2.26` ### Impact Deployments using the optional `voice-call` Twilio webhook path could accept replayed webhook events as fresh events when an attacker had one valid signed request and changed only the unsigned idempotency header. ### Technical Details The fix removes unsigned-header trust from Twilio replay/dedupe identity and binds replay/manager dedupe to authenticated request material. It also threads a verified request identity through provider parsing so dedupe uses verification-derived identity rather than mutable headers. ### Fix Commit(s) - `1aadf26f9acc399affabd859937a09468a9c5cb4` ### Release Process Note `patched_versions` is pre-set to the planned next release (`2026.2.26`). After the npm release is published, this advisory can be published without additional version-field edits. OpenClaw thanks @tdjackey for reporting.
Properties
- ghsa_id
- GHSA-gcj7-r3hg-m7w6
- severity
- low
- summary
- OpenClaw's voice-call Twilio replay dedupe now bound to authenticated webhook identity
- cvss_score
- 3.7
- cve_id
- GHSA-gcj7-r3hg-m7w6
- cvss_vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
- is_ghsa_only
- true
- ghsa_published
- 2026-03-03T22:25:37Z
- source_url
- https://github.com/advisories/GHSA-gcj7-r3hg-m7w6
- ghsa_updated
- 2026-03-03T22:25:38Z
Related Entities (4)
AFFECTS (1)
HAS_WEAKNESS (2)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph