CVE-2026-25474

HIGH EPSS 9.9%
Published Feb 19, 20264mo ago · Modified Jun 17, 20262w ago
7.5 CVSS 3.1
High
Find Similar
Published Feb 19, 2026 4mo ago
Last Modified Jun 17, 2026 2w ago

Description

OpenClaw is a personal AI assistant. In versions 2026.1.30 and below, if channels.telegram.webhookSecret is not set when in Telegram webhook mode, OpenClaw may accept webhook HTTP requests without verifying Telegram’s secret token header. In deployments where the webhook endpoint is reachable by an attacker, this can allow forged Telegram updates (for example spoofing message.from.id). If an attacker can reach the webhook endpoint, they may be able to send forged updates that are processed as if they came from Telegram. Depending on enabled commands/tools and configuration, this could lead to unintended bot actions. Note: Telegram webhook mode is not enabled by default. It is enabled only when `channels.telegram.webhookUrl` is configured. This issue has been fixed in version 2026.2.1.

CVSS Details

Base Score
7.5
Exploitability
3.9
Impact
3.6
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity High
Availability None

Threat Intelligence

EPSS Exploit Probability
9.9% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available

Weaknesses 1

CWE-345

Affected Products 1

VendorProductVersionRange
openclawopenclaw* <2026.2.1

References 6

  • github.com https://github.com/openclaw/openclaw/commit/3cbcba10cf30c2ffb898f0d8c7dfb929f15f8930
    Patch
  • github.com https://github.com/openclaw/openclaw/commit/5643a934799dc523ec2ef18c007e1aa2c386b670
    Patch
  • github.com https://github.com/openclaw/openclaw/commit/633fe8b9c17f02fcc68ecdb5ec212a5ace932f09
    Patch
  • github.com https://github.com/openclaw/openclaw/commit/ca92597e1f9593236ad86810b66633144b69314d
    Patch
  • github.com https://github.com/openclaw/openclaw/releases/tag/v2026.2.1
    ProductRelease Notes
  • github.com https://github.com/openclaw/openclaw/security/advisories/GHSA-mp5h-m6qj-6292
    ExploitMailing ListPatchVendor Advisory

Remediation

  • github.com https://github.com/openclaw/openclaw/commit/3cbcba10cf30c2ffb898f0d8c7dfb929f15f8930
    Patch
  • github.com https://github.com/openclaw/openclaw/commit/5643a934799dc523ec2ef18c007e1aa2c386b670
    Patch
  • github.com https://github.com/openclaw/openclaw/commit/633fe8b9c17f02fcc68ecdb5ec212a5ace932f09
    Patch
  • github.com https://github.com/openclaw/openclaw/commit/ca92597e1f9593236ad86810b66633144b69314d
    Patch
  • github.com https://github.com/openclaw/openclaw/security/advisories/GHSA-mp5h-m6qj-6292
    ExploitMailing ListPatchVendor Advisory