The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication path that allows unauthenticated webhook events in certain reverse-proxy or loc…
中危 CVSS 4.8
摘要
The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication path that allows unauthenticated webhook events in certain reverse-proxy or local routing configurations. Attackers can bypass webhook authentication by exploiting the loopback/proxy heuristics to send unauthenticated webhook events to the BlueBubbles plugin.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://github.com/openclaw/openclaw/commit/283029bdea23164ab7482b320cb420d1b90df806 Patch
- https://github.com/openclaw/openclaw/commit/6b2f2811dc623e5faaf2f76afaa9279637174590 Patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-5mx2-2mgw-x8rm Vendor Advisory
- https://www.vulncheck.com/advisories/openclaw-unauthenticated-webhook-access-via-passwordless-fallback-in-bluebubbles-plugin Third Party Advisory
时间线
- nvd_ingest NVD