mediumCVSS 6.5Vulnerability

GHSA-g7fw-3gjp-g5hf

### Summary Channel read actions could skip target allowlists. In affected versions, explicit read targets in Microsoft Teams, Feishu, Matrix, and Google Chat could reach channels or rooms outside the configured read policy. This advisory is scoped to caller-supplied targets for message, reaction, pin, member, and related metadata reads in the named plugins. It does not change OpenClaw's trusted-operator model or create per-user isolation within one Gateway. ### Impact A lower-trust sender or steered agent with access to a channel read action could retrieve content or metadata from a target excluded by the operator's channel allowlist. Practical impact depends on the bot account's platform permissions. ### Patched Versions The first stable patched version is `2026.8.1`. ### Mitigations upgrade each affected channel plugin to `2026.8.1` or later. Before upgrading, disable explicit-target read actions or limit the connected bot account to allowed channels at the platform level.

Properties

severity
medium
summary
OpenClaw: Channel read actions could skip target allowlists
cvss_score
6.5
retrieved_at
2026-10-06T03:05:59+00:00
ghsa_published
2026-10-05T23:27:44Z
source_url
https://github.com/advisories/GHSA-g7fw-3gjp-g5hf
ghsa_updated
2026-10-05T23:27:46Z
ghsa_id
GHSA-g7fw-3gjp-g5hf
last_source
GitHub Advisory Database
cve_id
GHSA-g7fw-3gjp-g5hf
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
signal_observed_at
2026-10-06T02:58:31+00:00
is_ghsa_only
true

Related Entities (11)

HAS_WEAKNESS (2)

→[Weakness]Incorrect Authorization
→[Weakness]Missing Authorization

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (4)

←[Software]npm/@openclaw/msteams
←[Software]npm/@openclaw/matrix
←[Software]npm/@openclaw/feishu
←[Software]npm/@openclaw/googlechat

AFFECTS (4)

→[Software]npm/@openclaw/matrix
→[Software]npm/@openclaw/feishu
→[Software]npm/@openclaw/googlechat
→[Software]npm/@openclaw/msteams

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-g7fw-3gjp-g5hf (CVSS 6.5) — Ninja Signal Threat Intelligence | Ninja Signal