CVE-2026-45002
MEDIUM
NVD
CVSS Score
5.3
Severity
MEDIUM
Published
May 11, 2026
Vendor
unknown
Description
OpenClaw before 2026.4.20 contains a hook session-key bypass vulnerability that allows attackers to circumvent the hooks.allowRequestSessionKey opt-in restriction. Attackers can render externally influenced session keys through templated hook mappings to bypass webhook routing isolation controls.