GHSA-qj22-xqjr-v83v
A missing sender-authorization check in Telegram `message_reaction` handling allowed unauthorized users to trigger reaction-derived system events. ## Affected Packages / Versions - Package: `openclaw` (npm) - Introduced: `2026.2.17` - Affected: `>= 2026.2.17` and `<= 2026.2.24` - Latest published at patch time: `2026.2.24` - Patched in release: `2026.2.25` ## Impact When reaction notifications are enabled, unauthorized Telegram senders could inject reaction system events despite configured DM/group authorization controls (`dmPolicy`, `allowFrom`, `groupPolicy`, `groupAllowFrom`). ## Fix Commit(s) - `e56b0cf1a04f992ac6ebc775899f48ea31687640` ## Release Process Note `patched_versions` is pre-set to the release (`2026.2.25`) so once npm release `2026.2.25` is published, this advisory can be published without further edits. OpenClaw thanks @tdjackey for reporting.
Properties
- ghsa_id
- GHSA-qj22-xqjr-v83v
- severity
- high
- summary
- OpenClaw's Telegram message_reaction authorization bypass allows unauthorized system-event injection
- cve_id
- GHSA-qj22-xqjr-v83v
- is_ghsa_only
- true
- ghsa_published
- 2026-03-03T18:09:08Z
- source_url
- https://github.com/advisories/GHSA-qj22-xqjr-v83v
- ghsa_updated
- 2026-03-03T18:09:08Z
Related Entities (3)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph