Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xg59-f45v-9r9j

Опубликовано: 31 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 2.3
CVSS3: 7.5

Описание

Duplicate Advisory: OpenClaw's MS Teams sender allowlist bypass when route allowlist is configured and sender allowlist is empty

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-g7cr-9h7q-4qxq. This link is maintained to preserve external references.

Original Description

OpenClaw before 2026.3.8 contains a sender allowlist bypass vulnerability in its Microsoft Teams plugin that allows unauthorized senders to bypass intended authorization checks. When a team/channel route allowlist is configured with an empty groupAllowFrom parameter, the message handler synthesizes wildcard sender authorization, permitting any sender in the matched team/channel to trigger replies in allowlisted Teams routes.

Пакеты

Наименование

openclaw

npm
Затронутые версииВерсия исправления

< 2026.3.8

2026.3.8

2.3 Low

CVSS4

7.5 High

CVSS3

Дефекты

CWE-863

2.3 Low

CVSS4

7.5 High

CVSS3

Дефекты

CWE-863