When only a route-level group allowlist was configured, sender policy resolution silently downgraded from allowlist to open instead of preserving the configured group policy.
Any member of an allowlisted Google Chat space or Zalouser group could interact with the bot even when the operator intended sender-level restrictions.
extensions/googlechat/src/monitor-access.ts, extensions/zalouser/src/monitor.ts
<= 2026.3.24>= 2026.3.282026.3.28 contains the fix.Fixed by commit e64a881ae0 (Channels: preserve routed group policy).
OpenClaw thanks @AntAISecurityLab for reporting.
{
"nvd_published_at": "2026-03-31T15:16:14Z",
"severity": "MODERATE",
"github_reviewed": true,
"cwe_ids": [
"CWE-863"
],
"github_reviewed_at": "2026-04-01T00:01:10Z"
}