highVulnerability

GHSA-qj22-xqjr-v83v

A missing sender-authorization check in Telegram `message_reaction` handling allowed unauthorized users to trigger reaction-derived system events. ## Affected Packages / Versions - Package: `openclaw` (npm) - Introduced: `2026.2.17` - Affected: `>= 2026.2.17` and `<= 2026.2.24` - Latest published at patch time: `2026.2.24` - Patched in release: `2026.2.25` ## Impact When reaction notifications are enabled, unauthorized Telegram senders could inject reaction system events despite configured DM/group authorization controls (`dmPolicy`, `allowFrom`, `groupPolicy`, `groupAllowFrom`). ## Fix Commit(s) - `e56b0cf1a04f992ac6ebc775899f48ea31687640` ## Release Process Note `patched_versions` is pre-set to the release (`2026.2.25`) so once npm release `2026.2.25` is published, this advisory can be published without further edits. OpenClaw thanks @tdjackey for reporting.

Properties

ghsa_id
GHSA-qj22-xqjr-v83v
severity
high
summary
OpenClaw's Telegram message_reaction authorization bypass allows unauthorized system-event injection
cve_id
GHSA-qj22-xqjr-v83v
is_ghsa_only
true
ghsa_published
2026-03-03T18:09:08Z
source_url
https://github.com/advisories/GHSA-qj22-xqjr-v83v
ghsa_updated
2026-03-03T18:09:08Z

Related Entities (3)

AFFECTS (1)

[Software]npm/OpenClaw

HAS_WEAKNESS (1)

[Weakness]Incorrect Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-qj22-xqjr-v83v — Ninja Signal Threat Intelligence | Ninja Signal