OpenClaw
OpenClaw
| Version / range | Status | Type |
|---|---|---|
| 0 to before 2026.8.1 | affected | semver |
| 2026.8.1 | unaffected | semver |
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that allows attackers to cancel unrelated sessions. An attacker with a webhook route secret can supply an arbitrary child session key to cancel ACP or subagent work outside the route's configured authority.
Risk score
2.3
CVSS 4.0
OpenClaw
| Version / range | Status | Type |
|---|---|---|
| 0 to before 2026.8.1 | affected | semver |
| 2026.8.1 | unaffected | semver |
2.3
CVSS 4.0
3.1
CVSS 3.1