GHSA-cg6c-q2hx-69h7: OpenClaw: Plivo V2 verified replay identity drifts on query-only variants
(updated )
Before v2026.3.23, the Plivo V2 verification path treated query-only variants of the same signed request as fresh verified work. Plivo V2 signatures authenticate baseUrl + nonce, but the replay key was derived from the full verification URL including the query string, so unsigned query-only changes minted a new verifiedRequestKey.
References
Code Behaviors & Features
Detect and mitigate GHSA-cg6c-q2hx-69h7 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →