
CVE-2026-25474 OpenClaw is a personal AI assistant. In versions 2026.1.30 and below, if channels.telegram.webhookSecret is not set when in Telegram webhook mode, OpenClaw may accept… https://www.cve.org/CVERecord?id=CVE-2026-25474
Post summary
The post announces CVE‑2026‑25474, noting that OpenClaw’s Telegram webhook mode can accept requests when the webhookSecret is unset, potentially exposing the system to unauthorized access.

