BlueBubbles Group Reactions Bypass requireMention and Still Enqueue Agent-Visible System Events
openclaw<= 2026.3.242026.3.252026.3.24BlueBubbles group reaction events previously bypassed requireMention and still enqueued agent-visible system events in groups that were supposed to stay mention-gated. Commit f8c98630785288cc1f1d0893503ef3b653a3cede applies the reaction path to the same mention gate as normal group messages.
Verified vulnerable on tag v2026.3.24 and fixed on main by commit f8c98630785288cc1f1d0893503ef3b653a3cede.
f8c98630785288cc1f1d0893503ef3b653a3cede{
"github_reviewed_at": "2026-03-27T22:32:06Z",
"nvd_published_at": null,
"cwe_ids": [
"CWE-288",
"CWE-863"
],
"severity": "MODERATE",
"github_reviewed": true
}