Under iMessage groupPolicy=allowlist, group authorization could be satisfied by sender identities coming from the DM pairing store, broadening DM trust into group contexts.
Affected component: src/imessage/monitor/monitor-provider.ts.
Vulnerable logic derived effectiveGroupAllowFrom using both the static group allowlist and DM pairing-store identities (storeAllowFrom). This allowed a sender approved via DM pairing to satisfy group authorization in groups even if the sender/chat was not explicitly present in groupAllowFrom.
This weakens boundary separation between DM pairing and group allowlist authorization.
openclaw (npm): affected <= 2026.2.13clawdbot (npm): affected <= 2026.1.24-3openclaw/openclaw@872079d42fe105ece2900a1dd6ab321b92da2d59openclaw/openclaw@90d1e9cd71419168b2faa54a759b124a3eacfae7Thanks @vincentkoc for reporting.
{
"cwe_ids": [
"CWE-284",
"CWE-863"
],
"github_reviewed": true,
"github_reviewed_at": "2026-02-18T00:43:54Z",
"nvd_published_at": "2026-02-20T00:16:15Z",
"severity": "MODERATE"
}