GHSA-4rj2-gpmh-qq5x: OpenClaw has an inbound allowlist policy bypass in voice-call extension (empty caller ID + suffix matching)
An authentication bypass in the optional voice-call extension/plugin allowed unapproved or anonymous callers to reach the voice-call agent when inbound policy was set to allowlist or pairing.
Deployments that do not install/enable the voice-call extension are not affected.
References
Code Behaviors & Features
Detect and mitigate GHSA-4rj2-gpmh-qq5x with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →