OpenClaw Improper Authentication Verification Vulnerability in Google Chat Webhook Handling

Vulnerability

A vulnerability exists in OpenClaw versions prior to 2026.3.22, allowing improper authentication verification in the Google Chat app-url webhook handling. This vulnerability enables attackers to bypass webhook authentication by using non-deployment add-on principals, thereby executing unauthorized actions through the Google Chat integration.

Impact

Exploitation of this vulnerability allows for authentication bypass, enabling unauthorized actions to be performed via the Google Chat integration.

Reproduction

To reproduce this vulnerability, send a request to a Google Chat webhook with a non-deployment add-on principal. The webhook will accept the request without proper authentication verification, allowing unauthorized actions to be executed.

Remediation

Users can update to OpenClaw version 2026.3.22 or later to address this vulnerability.

Added: Apr 10, 2026, 12:12 AM
Updated: Apr 10, 2026, 12:12 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.7
remediation
0.0
relevance
5.5
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.