GHSA-jqpf-vj28-9v7r

Suggest an improvement
Source
https://github.com/advisories/GHSA-jqpf-vj28-9v7r
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-jqpf-vj28-9v7r/GHSA-jqpf-vj28-9v7r.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jqpf-vj28-9v7r
Withdrawn
2026-03-20T13:55:52Z
Published
2026-03-19T03:30:57Z
Modified
2026-03-20T14:01:35.004342Z
Severity
  • 7.0 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L CVSS Calculator
  • 8.3 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
Duplicate Advisory: Synology Chat dmPolicy=allowlist failed open on empty allowedUserIds, allowing unauthorized agent dispatch
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-gw85-xp4q-5gp9. This link is maintained to preserve external references.

Original Description

OpenClaw versions 2026.2.22 and 2026.2.23 contain an authorization bypass vulnerability in the synology-chat channel plugin where dmPolicy set to allowlist with empty allowedUserIds fails open. Attackers with Synology sender access can bypass authorization checks and trigger unauthorized agent dispatch and downstream tool actions.

Database specific
{
    "github_reviewed": true,
    "github_reviewed_at": "2026-03-20T13:55:52Z",
    "cwe_ids": [
        "CWE-863"
    ],
    "severity": "HIGH",
    "nvd_published_at": "2026-03-19T02:16:05Z"
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
2026.2.22
Last affected
2026.2.23

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-jqpf-vj28-9v7r/GHSA-jqpf-vj28-9v7r.json"