CVE-2026-41337

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
23/04/2026
Last modified:
24/04/2026

Description

OpenClaw before 2026.3.31 contains a callback origin mutation vulnerability in Plivo voice-call replay that allows attackers to mutate in-process callback origin before replay rejection. Attackers with captured valid callbacks for live calls can exploit this to manipulate callback origins during the replay process.