CVE-2026-43566: Openclaw Heartbeat Wake Pending Events Omittedcve-2026-43566-openclaw-heartbeat-wake-pending-events-omitted
Heartbeat owner-downgrade logic computes shouldInspectPendingEvents (or ForceSenderIsOwnerFalse) without considering wake-triggered runs or untrusted pending events. CVE-2026-43566: webhook 'hook:wake' system events were excluded from the inspection set, allowing untrusted webhook payloads to be drained while senderIsOwner remained true. The patched code mus