OpenClaw Webhook Secret Validation Vulnerability in Telegram Webhook Mode

Vulnerability

A vulnerability exists in OpenClaw versions prior to 2026.2.2, where the application fails to properly validate webhook secrets in Telegram webhook mode. This oversight allows unauthenticated HTTP POST requests to the webhook endpoint, which can include attacker-controlled JSON payloads. Exploiting this vulnerability, remote attackers can forge Telegram updates by manipulating the message.from.id and chat.id fields. This can bypass sender allowlists and enable the execution of privileged bot commands.

Impact

Exploitation of this vulnerability leads to an authorization bypass, allowing attackers to execute privileged commands via a Telegram bot.

Reproduction

To reproduce this vulnerability, send an HTTP POST request to the Telegram webhook endpoint without a valid webhook secret. Include a JSON payload that spoof message.from.id and chat.id fields to bypass sender allowlists and trigger a privileged command on the bot.

Remediation

Users can update to OpenClaw version 2026.2.2 or later, where this vulnerability has been addressed.

Added: Mar 5, 2026, 10:44 PM
Updated: Mar 5, 2026, 10:44 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.7
remediation
0.0
relevance
3.5
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.