Описание
OpenClaw versions prior to 2026.2.22 with the optional BlueBubbles plugin contain an access control bypass vulnerability where empty allowFrom configuration causes dmPolicy pairing and allowlist restrictions to be ineffective. Remote attackers can send direct messages to BlueBubbles accounts by exploiting the misconfigured allowlist validation logic to bypass intended sender authorization checks.
Ссылки
- Patch
- Patch
- Patch
- Patch
- Vendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2026.2.22 (исключая)
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 17%
0.00255
Низкий
6.5 Medium
CVSS3
4.8 Medium
CVSS3
Дефекты
CWE-863
Связанные уязвимости
github
5 месяцев назад
OpenClaw: BlueBubbles (optional plugin) pairing/allowlist mismatch when allowFrom is empty
CVSS3: 6.5
fstec
6 месяцев назад
Уязвимость плагина BlueBubbles ИИ-агента OpenClaw (ранее - ClawdBot или MoltBot), позволяющая нарушителю обойти существующие механизмы безопасности
EPSS
Процентиль: 17%
0.00255
Низкий
6.5 Medium
CVSS3
4.8 Medium
CVSS3
Дефекты
CWE-863