mediumVulnerability

GHSA-rxmx-g7hr-8mx4

## Summary Before OpenClaw 2026.4.2, Zalo webhook replay dedupe keys were not scoped strongly enough across chat and sender dimensions. Legitimate events from different conversations or senders could collide and be dropped as duplicates. ## Impact Cross-conversation or cross-sender collisions could cause silent message suppression and break bot workflows. This was an availability issue in webhook event processing. ## Affected Packages / Versions - Package: `openclaw` (npm) - Affected versions: `<= 2026.4.1` - Patched versions: `>= 2026.4.2` - Latest published npm version: `2026.4.1` ## Fix Commit(s) - `ef7c553dd16ee579f1d1a363f5881a99726c1412` — scope Zalo webhook replay dedupe across the missing event dimensions ## Release Process Note The fix is present on `main` and is staged for OpenClaw `2026.4.2`. Publish this advisory after the `2026.4.2` npm release is live. Thanks @D0ub1e-D for reporting.

Properties

ghsa_id
GHSA-rxmx-g7hr-8mx4
severity
medium
summary
OpenClaw: Zalo replay dedupe keys could suppress messages across chats or senders
cve_id
GHSA-rxmx-g7hr-8mx4
is_ghsa_only
true
ghsa_published
2026-04-07T18:15:59Z
source_url
https://github.com/advisories/GHSA-rxmx-g7hr-8mx4
ghsa_updated
2026-04-07T18:16:00Z

Related Entities (5)

AFFECTS (1)

[Software]npm/OpenClaw

VULNERABLE_TO (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (2)

[Weakness]Acceptance of Extraneous Untrusted Data With Trusted Data
[Weakness]Expected Behavior Violation

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph