Описание
OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are incorrectly treated as group allowlist identities when dmPolicy=pairing and groupPolicy=allowlist. Remote attackers can send messages and reactions as DM-paired identities without explicit groupAllowFrom membership to bypass group sender authorization checks.
Ссылки
- Patch
- Vendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2026.2.26 (исключая)
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 21%
0.00295
Низкий
3.1 Low
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-863
Связанные уязвимости
CVSS3: 4.3
github
5 месяцев назад
OpenClaw has a BlueBubbles group allowlist mismatch via DM pairing-store fallback
EPSS
Процентиль: 21%
0.00295
Низкий
3.1 Low
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-863