GHSA-w76h-8m22-hpgh

Suggest an improvement
Source
https://github.com/advisories/GHSA-w76h-8m22-hpgh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-w76h-8m22-hpgh/GHSA-w76h-8m22-hpgh.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-w76h-8m22-hpgh
Aliases
Downstream
Published
2026-03-03T18:10:12Z
Modified
2026-03-20T21:37:39Z
Severity
  • 6.0 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L CVSS Calculator
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenClaw's MSTeams attachment redirect handling could bypass configured media host allowlists
Details

Summary

In OpenClaw MSTeams media download flows, redirect handling could bypass configured mediaAllowHosts checks in specific attachment paths. Redirect chains were not consistently constrained to allowlisted targets before accepting fetched content.

Affected Packages / Versions

  • Package: openclaw (npm)
  • Affected versions: <= 2026.2.21-2 (latest published at triage time)
  • Fixed in: 2026.2.22 (planned next release)

Impact

Attackers able to supply or influence attachment URLs could force redirect chains to non-allowlisted targets, weakening SSRF boundary controls for MSTeams media ingestion.

Fix Commit(s)

  • 73d93dee64127a26f1acd09d0403b794cdeb4f5c
  • b34097f62df9d1960cc22600269cd3f3284e2124

Release Process Note

patched_versions is pre-set to the planned next release (2026.2.22). Once that npm release is published, this advisory can be published without further version-field edits.

OpenClaw thanks @tdjackey for reporting.

Database specific
{
    "cwe_ids":  [
        "CWE-918"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-03T18:10:12Z",
    "nvd_published_at":  "2026-03-19T22:16:39Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / openclaw

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2026.2.22

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-w76h-8m22-hpgh/GHSA-w76h-8m22-hpgh.json"