mediumVulnerability

GHSA-j26j-7qc4-3mrf

### Summary In `openclaw` MS Teams file-consent flow, pending uploads were authorized by `uploadId` alone. `fileConsent/invoke` did not verify the invoke conversation against the conversation that created the pending upload. ### Impact An attacker who obtained a valid `uploadId` within TTL could trigger cross-conversation upload completion (accept path) or cancel a victim pending upload (decline path). ### Technical Details - Pending uploads stored `conversationId`, but invoke handling consumed by `uploadId` only. - The invoke path did not enforce conversation binding before `uploadToConsentUrl(...)` and pending-upload removal. - Fix binds accept/decline handling to normalized conversation id match before consuming pending upload state. ### Affected Packages / Versions - Package: `openclaw` (npm) - Latest published npm version (as of February 26, 2026): `2026.2.24` - Vulnerable range: `<= 2026.2.24` - Patched in release: `2026.2.25` ### Remediation Upgrade to `openclaw` `2026.2.25` (or later) once published. ### Fix Commit(s) - `347f7b9550064f5f5b33c6e07f64e85b9657b6f1` ### Release Process Note `patched_versions` is pre-set to the release (`2026.2.25`). Advisory published with npm release `2026.2.25`. OpenClaw thanks @tdjackey for reporting.

Properties

ghsa_id
GHSA-j26j-7qc4-3mrf
severity
medium
summary
OpenClaw: MS Teams fileConsent/invoke missing conversation binding allowed cross-conversation pending-upload consumption
cve_id
GHSA-j26j-7qc4-3mrf
is_ghsa_only
true
ghsa_published
2026-03-03T21:36:49Z
source_url
https://github.com/advisories/GHSA-j26j-7qc4-3mrf
ghsa_updated
2026-03-03T21:36:50Z

Related Entities (4)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (2)

[Weakness]Missing Authorization
[Weakness]Authorization Bypass Through User-Controlled Key

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph