GHSA-g7fw-3gjp-g5hf

Suggest an improvement
Source
https://github.com/advisories/GHSA-g7fw-3gjp-g5hf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-g7fw-3gjp-g5hf/GHSA-g7fw-3gjp-g5hf.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-g7fw-3gjp-g5hf
Aliases
Published
2026-10-05T23:27:44Z
Modified
2026-10-05T23:45:09Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
OpenClaw: Channel read actions could skip target allowlists
Details

Summary

Channel read actions could skip target allowlists. In affected versions, explicit read targets in Microsoft Teams, Feishu, Matrix, and Google Chat could reach channels or rooms outside the configured read policy.

This advisory is scoped to caller-supplied targets for message, reaction, pin, member, and related metadata reads in the named plugins. It does not change OpenClaw's trusted-operator model or create per-user isolation within one Gateway.

Impact

A lower-trust sender or steered agent with access to a channel read action could retrieve content or metadata from a target excluded by the operator's channel allowlist. Practical impact depends on the bot account's platform permissions.

Patched Versions

The first stable patched version is 2026.8.1.

Mitigations

upgrade each affected channel plugin to 2026.8.1 or later. Before upgrading, disable explicit-target read actions or limit the connected bot account to allowed channels at the platform level.

Database specific
{
    "cwe_ids":  [
        "CWE-862",
        "CWE-863"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-10-05T23:27:44Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / @openclaw/msteams

Package

Name
@openclaw/msteams
View open source insights on deps.dev
Purl
pkg:npm/%40openclaw/msteams

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2026.8.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-g7fw-3gjp-g5hf/GHSA-g7fw-3gjp-g5hf.json"

npm / @openclaw/feishu

Package

Name
@openclaw/feishu
View open source insights on deps.dev
Purl
pkg:npm/%40openclaw/feishu

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2026.8.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-g7fw-3gjp-g5hf/GHSA-g7fw-3gjp-g5hf.json"

npm / @openclaw/matrix

Package

Name
@openclaw/matrix
View open source insights on deps.dev
Purl
pkg:npm/%40openclaw/matrix

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2026.8.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-g7fw-3gjp-g5hf/GHSA-g7fw-3gjp-g5hf.json"

npm / @openclaw/googlechat

Package

Name
@openclaw/googlechat
View open source insights on deps.dev
Purl
pkg:npm/%40openclaw/googlechat

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2026.8.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-g7fw-3gjp-g5hf/GHSA-g7fw-3gjp-g5hf.json"