GHSA-j26j-7qc4-3mrf
### Summary In `openclaw` MS Teams file-consent flow, pending uploads were authorized by `uploadId` alone. `fileConsent/invoke` did not verify the invoke conversation against the conversation that created the pending upload. ### Impact An attacker who obtained a valid `uploadId` within TTL could trigger cross-conversation upload completion (accept path) or cancel a victim pending upload (decline path). ### Technical Details - Pending uploads stored `conversationId`, but invoke handling consumed by `uploadId` only. - The invoke path did not enforce conversation binding before `uploadToConsentUrl(...)` and pending-upload removal. - Fix binds accept/decline handling to normalized conversation id match before consuming pending upload state. ### Affected Packages / Versions - Package: `openclaw` (npm) - Latest published npm version (as of February 26, 2026): `2026.2.24` - Vulnerable range: `<= 2026.2.24` - Patched in release: `2026.2.25` ### Remediation Upgrade to `openclaw` `2026.2.25` (or later) once published. ### Fix Commit(s) - `347f7b9550064f5f5b33c6e07f64e85b9657b6f1` ### Release Process Note `patched_versions` is pre-set to the release (`2026.2.25`). Advisory published with npm release `2026.2.25`. OpenClaw thanks @tdjackey for reporting.
Properties
- ghsa_id
- GHSA-j26j-7qc4-3mrf
- severity
- medium
- summary
- OpenClaw: MS Teams fileConsent/invoke missing conversation binding allowed cross-conversation pending-upload consumption
- cve_id
- GHSA-j26j-7qc4-3mrf
- is_ghsa_only
- true
- ghsa_published
- 2026-03-03T21:36:49Z
- source_url
- https://github.com/advisories/GHSA-j26j-7qc4-3mrf
- ghsa_updated
- 2026-03-03T21:36:50Z
Related Entities (4)
AFFECTS (1)
HAS_WEAKNESS (2)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph