GHSA-g34w-4xqq-h79m

Suggest an improvement
Source
https://github.com/advisories/GHSA-g34w-4xqq-h79m
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-g34w-4xqq-h79m/GHSA-g34w-4xqq-h79m.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-g34w-4xqq-h79m
Aliases
Downstream
Published
2026-02-18T00:43:54Z
Modified
2026-02-20T16:54:58Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
OpenClaw iMessage group allowlist authorization inherited DM pairing-store identities
Details

Summary

Under iMessage groupPolicy=allowlist, group authorization could be satisfied by sender identities coming from the DM pairing store, broadening DM trust into group contexts.

Details

Affected component: src/imessage/monitor/monitor-provider.ts.

Vulnerable logic derived effectiveGroupAllowFrom using both the static group allowlist and DM pairing-store identities (storeAllowFrom). This allowed a sender approved via DM pairing to satisfy group authorization in groups even if the sender/chat was not explicitly present in groupAllowFrom.

This weakens boundary separation between DM pairing and group allowlist authorization.

Affected Packages / Versions

  • openclaw (npm): affected <= 2026.2.13
  • clawdbot (npm): affected <= 2026.1.24-3

Fix Commit(s)

  • openclaw/openclaw@872079d42fe105ece2900a1dd6ab321b92da2d59
  • openclaw/openclaw@90d1e9cd71419168b2faa54a759b124a3eacfae7

Thanks @vincentkoc for reporting.

Database specific
{
    "cwe_ids":  [
        "CWE-284",
        "CWE-863"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-02-18T00:43:54Z",
    "nvd_published_at":  "2026-02-20T00:16:15Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2026.2.14

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-g34w-4xqq-h79m/GHSA-g34w-4xqq-h79m.json"

npm / clawdbot

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2026.2.14

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-g34w-4xqq-h79m/GHSA-g34w-4xqq-h79m.json"