OpenClaw Improper Authentication Verification Vulnerability in Google Chat Webhook Handling
Vulnerability
A vulnerability exists in OpenClaw versions prior to 2026.3.22, allowing improper authentication verification in the Google Chat app-url webhook handling. This vulnerability enables attackers to bypass webhook authentication by using non-deployment add-on principals, thereby executing unauthorized actions through the Google Chat integration.
Impact
Exploitation of this vulnerability allows for authentication bypass, enabling unauthorized actions to be performed via the Google Chat integration.
Reproduction
To reproduce this vulnerability, send a request to a Google Chat webhook with a non-deployment add-on principal. The webhook will accept the request without proper authentication verification, allowing unauthorized actions to be executed.
Remediation
Users can update to OpenClaw version 2026.3.22 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
