mediumCVSS 7.3Vulnerability

GHSA-p6j4-wvmc-vx2h

### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-vfg3-pqpq-93m4. This link is maintained to preserve external references. ### Original Description OpenClaw before 2026.3.22 performs cite expansion before completing channel and DM authorization checks, allowing cite work and content handling prior to final auth decisions. Attackers can exploit this timing vulnerability to access or manipulate content before proper authorization validation occurs.

Properties

ghsa_id
GHSA-p6j4-wvmc-vx2h
severity
medium
summary
Duplicate Advisory: OpenClaw: Tlon cite expansion happens before channel and DM authorization is complete
cvss_score
7.3
cve_id
GHSA-p6j4-wvmc-vx2h
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
is_ghsa_only
true
ghsa_published
2026-04-10T00:30:30Z
source_url
https://github.com/advisories/GHSA-p6j4-wvmc-vx2h
ghsa_updated
2026-04-10T20:20:18Z

Related Entities (4)

AFFECTS (1)

[Software]npm/OpenClaw

VULNERABLE_TO (1)

[Software]npm/OpenClaw

REPORTED_BY (1)

[Source]GitHub Advisory Database

HAS_WEAKNESS (1)

[Weakness]Incorrect Behavior Order

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-p6j4-wvmc-vx2h (CVSS 7.3) — Ninja Signal Threat Intelligence | Ninja Signal