GHSA-3m3q-x3gj-f79x: OpenClaw optional voice-call plugin: webhook verification may be bypassed behind certain proxy configurations
In certain reverse-proxy / forwarding setups, webhook verification can be bypassed if untrusted forwarded headers are accepted.
References
Code Behaviors & Features
Detect and mitigate GHSA-3m3q-x3gj-f79x with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →