Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fjfc-7x5g-g52w

Опубликовано: 17 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 2.3
CVSS3: 5.4

Описание

OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names. Attackers with lower-trust access can perform actions requiring stronger authorization by exploiting the mutable display name binding in the affected feature.

OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names. Attackers with lower-trust access can perform actions requiring stronger authorization by exploiting the mutable display name binding in the affected feature.

EPSS

Процентиль: 5%
0.00155
Низкий

2.3 Low

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 5.4
nvd
29 дней назад

OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names. Attackers with lower-trust access can perform actions requiring stronger authorization by exploiting the mutable display name binding in the affected feature.

EPSS

Процентиль: 5%
0.00155
Низкий

2.3 Low

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-290