GHSA-m6fx-m8hc-572m

Suggest an improvement
Source
https://github.com/advisories/GHSA-m6fx-m8hc-572m
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-m6fx-m8hc-572m/GHSA-m6fx-m8hc-572m.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-m6fx-m8hc-572m
Aliases
Downstream
Published
2026-04-03T03:15:56Z
Modified
2026-05-05T16:08:45Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenClaw: Telegram audio preflight transcription enables resource consumption by unauthorized senders
Details

Summary

Telegram audio preflight transcription enables resource consumption by unauthorized senders

Current Maintainer Triage

  • Status: narrow
  • Normalized severity: medium
  • Assessment: v2026.3.28 still lets unauthorized Telegram group senders trigger audio preflight before allowlist enforcement, but the real impact is resource or billing burn rather than direct data exposure or host compromise.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Latest published npm version: 2026.3.31
  • Vulnerable version range: <=2026.3.28
  • Patched versions: >= 2026.3.31
  • First stable tag containing the fix: v2026.3.31

Fix Commit(s)

  • c4fa8635d03943ffe9e294d501089521dca635c5 — 2026-03-30T12:19:31+01:00

OpenClaw thanks @AntAISecurityLab for reporting.

Database specific
{
    "cwe_ids":  [
        "CWE-408",
        "CWE-770"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-04-03T03:15:56Z",
    "nvd_published_at":  "2026-04-21T00:16:31Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2026.3.31

Database specific

last_known_affected_version_range
"<= 2026.3.28"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-m6fx-m8hc-572m/GHSA-m6fx-m8hc-572m.json"