GHSA-5mx2-2mgw-x8rm: OpenClaw: BlueBubbles beta plugin webhook auth hardening (remove passwordless fallback)
BlueBubbles webhook auth in the optional beta iMessage plugin allowed a passwordless fallback path. In some reverse-proxy/local routing setups, this could allow unauthenticated webhook events.
References
Code Behaviors & Features
Detect and mitigate GHSA-5mx2-2mgw-x8rm with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →