mediumCVSS 4.8Vulnerability

GHSA-g8mc-c5f2-mqg7

### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-rqp8-q22p-5j9q This link is maintained to preserve external references. ### Original Description OpenClaw before 2026.3.22 contains a webhook path route replacement vulnerability in the Synology Chat extension that allows attackers to collapse multi-account configurations onto shared webhook paths. Attackers can exploit inherited or duplicate webhook paths to bypass per-account DM access control policies and replace route ownership across accounts.

Properties

ghsa_id
GHSA-g8mc-c5f2-mqg7
severity
medium
summary
Duplicate Advisory: OpenClaw Bypasses DM Policy Separation via Synology Chat Webhook Path Collision
cvss_score
4.8
cve_id
GHSA-g8mc-c5f2-mqg7
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
is_ghsa_only
true
ghsa_published
2026-04-10T00:30:30Z
source_url
https://github.com/advisories/GHSA-g8mc-c5f2-mqg7
ghsa_updated
2026-04-10T20:19:53Z

Related Entities (4)

AFFECTS (1)

[Software]npm/OpenClaw

VULNERABLE_TO (1)

[Software]npm/OpenClaw

REPORTED_BY (1)

[Source]GitHub Advisory Database

HAS_WEAKNESS (1)

[Weakness]Use of Incorrectly-Resolved Name or Reference

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-g8mc-c5f2-mqg7 (CVSS 4.8) — Ninja Signal Threat Intelligence | Ninja Signal