GHSA-vfg3-pqpq-93m4

Suggest an improvement
Source
https://github.com/advisories/GHSA-vfg3-pqpq-93m4
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-vfg3-pqpq-93m4/GHSA-vfg3-pqpq-93m4.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vfg3-pqpq-93m4
Aliases
  • CVE-2026-35637
Downstream
Published
2026-03-26T21:27:49Z
Modified
2026-04-10T20:31:24.445655Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenClaw: Tlon cite expansion happens before channel and DM authorization is complete
Details

Summary

Tlon cite expansion happened before channel and DM authorization completed, allowing cite work and content handling before the final auth decision.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Affected: < 2026.3.22
  • Fixed: >= 2026.3.22
  • Latest released tag checked: v2026.3.23-2 (630f1479c44f78484dfa21bb407cbe6f171dac87)
  • Latest published npm version checked: 2026.3.23-2

Fix Commit(s)

  • 3cbf932413e41d1836cb91aed1541a28a3122f93
  • ebee4e2210e1f282a982c7ef2ad79d77a572fc87

Release Status

The fix shipped in v2026.3.22 and remains present in v2026.3.23 and v2026.3.23-2.

Code-Level Confirmation

  • extensions/tlon/src/monitor/index.ts now defers cite expansion until after authorization and preserves explicit empty-allowlist semantics.
  • extensions/tlon/src/monitor/utils.ts and extensions/tlon/src/security.test.ts ship the deferred cite expansion behavior and regressions.

OpenClaw thanks @zpbrent for reporting.

Database specific
{
    "github_reviewed": true,
    "github_reviewed_at": "2026-03-26T21:27:49Z",
    "cwe_ids": [
        "CWE-863"
    ],
    "severity": "MODERATE",
    "nvd_published_at": null
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2026.3.22

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-vfg3-pqpq-93m4/GHSA-vfg3-pqpq-93m4.json"