Описание
OpenClaw versions prior to 2026.2.1 with the voice-call extension installed and enabled contain an authentication bypass vulnerability in inbound allowlist policy validation that accepts empty caller IDs and uses suffix-based matching instead of strict equality. Remote attackers can bypass inbound access controls by placing calls with missing caller IDs or numbers ending with allowlisted digits to reach the voice-call agent and execute tools.
Ссылки
- Patch
- ExploitVendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2026.2.2 (исключая)
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 50%
0.00652
Низкий
9.4 Critical
CVSS3
9.8 Critical
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-303
Связанные уязвимости
CVSS3: 9.4
github
7 месяцев назад
OpenClaw has an inbound allowlist policy bypass in voice-call extension (empty caller ID + suffix matching)
EPSS
Процентиль: 50%
0.00652
Низкий
9.4 Critical
CVSS3
9.8 Critical
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-303