highCVSS 6.5Vulnerability

GHSA-j56c-wpqm-h24x

### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-cg6c-q2hx-69h7. This link is maintained to preserve external references. ### Original Description OpenClaw before 2026.3.23 contains a replay identity vulnerability in Plivo V2 signature verification that allows attackers to bypass replay protection by modifying query parameters. The verification path derives replay keys from the full URL including query strings instead of the canonicalized base URL, enabling attackers to mint new verified request keys through unsigned query-only changes to signed requests.

Properties

ghsa_id
GHSA-j56c-wpqm-h24x
summary
Duplicate Advisory: OpenClaw: Plivo V2 verified replay identity drifts on query-only variants
severity
high
cvss_score
6.5
cve_id
GHSA-j56c-wpqm-h24x
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
is_ghsa_only
true
ghsa_published
2026-04-10T00:30:29Z
source_url
https://github.com/advisories/GHSA-j56c-wpqm-h24x
ghsa_updated
2026-04-10T20:18:47Z

Related Entities (4)

AFFECTS (1)

[Software]npm/OpenClaw

VULNERABLE_TO (1)

[Software]npm/OpenClaw

REPORTED_BY (1)

[Source]GitHub Advisory Database

HAS_WEAKNESS (1)

[Weakness]Authentication Bypass by Capture-replay

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-j56c-wpqm-h24x (CVSS 6.5) — Ninja Signal Threat Intelligence | Ninja Signal