#VU125242 Improper control of a resource through its lifetime in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to alter the in-process callback origin.
The vulnerability exists due to improper state management in the Plivo callback origin handling logic when replaying a captured valid callback for a live call. A remote attacker can replay a captured valid callback to alter the in-process callback origin.
Replay rejection occurs only after the callback origin has already been mutated.