OpenClaw: Google Chat app-url webhook auth accepted non-deployment add-on principals
Moderate severity
GitHub Reviewed
Published
Mar 24, 2026
in
openclaw/openclaw
•
Updated Apr 18, 2026
Description
Published to the GitHub Advisory Database
Mar 26, 2026
Reviewed
Mar 26, 2026
Last updated
Apr 18, 2026
Summary
Google Chat app-url webhook verification accepted add-on principals outside the intended deployment binding.
Affected Packages / Versions
openclaw(npm)v2026.3.23-2(630f1479c44f78484dfa21bb407cbe6f171dac87)2026.3.23-2Fix Commit(s)
a47722de7e3c9cbda8d5512747ca7e3bb8f6ee66Release Status
The fix shipped in
v2026.3.22and remains present inv2026.3.23andv2026.3.23-2.Code-Level Confirmation
OpenClaw thanks @ijxpwastaken for reporting.
References