OpenClaw versions prior to 2026.3.25 contain a pre-authentication rate-limit bypass vulnerability in webhook token validation that enables attackers to brute-force weak webhook secrets through rapid successive requests without throttling or authentication penalties. The vulnerability stems from the application rejecting invalid tokens without implementing rate limiting on authentication attempts, thereby creating an attack surface for credential enumeration. The vulnerability carries a CVSS 3.1 score of 6.5 (Medium), with a network-based attack vector requiring no special privileges or user interaction. While the attack complexity is low, the impact is limited to confidentiality and integrity breaches, with no availability impact anticipated. The EPSS score of 0.000730000 indicates this vulnerability poses a lower exploitation probability relative to the broader CVE landscape. Currently, this vulnerability is not listed on the Known Exploited Vulnerabilities catalog and shows no evidence of active exploitation in the wild. No public exploit code is widely available, and community attention remains minimal. Organizations running OpenClaw should prioritize upgrading to version 2026.3.25 or later as part of routine patch management, particularly for systems exposing webhook interfaces to untrusted networks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2026.3.25CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
< 2026.3.25CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.