A missing sender-authorization check in Telegram message_reaction handling allowed unauthorized users to trigger reaction-derived system events.
openclaw (npm)2026.2.17>= 2026.2.17 and <= 2026.2.242026.2.242026.2.25When reaction notifications are enabled, unauthorized Telegram senders could inject reaction system events despite configured DM/group authorization controls (dmPolicy, allowFrom, groupPolicy, groupAllowFrom).
e56b0cf1a04f992ac6ebc775899f48ea31687640patched_versions is pre-set to the release (2026.2.25) so once npm release 2026.2.25 is published, this advisory can be published without further edits.
OpenClaw thanks @tdjackey for reporting.
{
"cwe_ids": [
"CWE-863"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-03T18:09:08Z",
"nvd_published_at": null,
"severity": "HIGH"
}