
Cloud Vulnerability DB
A community-led vulnerabilities database
BlueBubbles webhook auth in the optional beta iMessage plugin allowed a passwordless fallback path. In some reverse-proxy/local routing setups, this could allow unauthenticated webhook events.
extensions/bluebubbles webhook handleropenclaw/openclaw (npm)2026.2.19-2<=2026.2.19-2main; planned patched release: 2026.2.21 (>=2026.2.21)The vulnerable implementation had multiple auth branches, including a passwordless fallback with loopback/proxy heuristics. The fix now uses one authentication codepath:
channels.bluebubbles.passwordpassword when serverUrl is setBlueBubbles is an optional beta iMessage plugin, and onboarding/channel-add flows already require a password. Practical exposure is mainly custom/manual configurations that omitted webhook password authentication.
>=2026.2.21, planned).?password=<password> or x-password).6b2f2811dc623e5faaf2f76afaa9279637174590283029bdea23164ab7482b320cb420d1b90df806patched_versions is pre-set to the planned next release (2026.2.21) so once npm release is out, advisory publish can proceed without additional ticket edits.
OpenClaw thanks @zpbrent for reporting.
Source: NVD
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."