GHSA-g7fw-3gjp-g5hfMedium· 6.5▾ SunlitOpenClaw: Channel read actions could skip target allowlists
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Channel read actions could skip target allowlists. In affected versions, explicit read targets in Microsoft Teams, Feishu, Matrix, and Google Chat could reach channels or rooms outside the configured read policy.
This advisory is scoped to caller-supplied targets for message, reaction, pin, member, and related metadata reads in the named plugins. It does not change OpenClaw's trusted-operator model or create per-user isolation within one Gateway.
A lower-trust sender or steered agent with access to a channel read action could retrieve content or metadata from a target excluded by the operator's channel allowlist. Practical impact depends on the bot account's platform permissions.
The first stable patched version is 2026.8.1.
upgrade each affected channel plugin to 2026.8.1 or later. Before upgrading, disable explicit-target read actions or limit the connected bot account to allowed channels at the platform level.
@openclaw/msteams < 2026.8.1@openclaw/feishu < 2026.8.1@openclaw/matrix < 2026.8.1@openclaw/googlechat < 2026.8.1Upgrade to a patched release:
@openclaw/msteams 2026.8.1@openclaw/feishu 2026.8.1@openclaw/matrix 2026.8.1@openclaw/googlechat 2026.8.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-100582Medium· 6.5OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8.1 do not enforce the configured channel read allowlist for caller-supplied explicit read targets in message, reactio…
CVE-2025-12925High· 7.3A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224
GHSA-2q7j-2vhx-56g8High· 8.1OpenClaw Feishu tools could ignore per-account disablement
GHSA-w8wf-3qvj-6xqfHigh· 8.1OpenClaw Feishu permission tools could ignore per-account disablement
GHSA-w4v6-g3wm-w36cCriticalOpenClaw: QQBot admin commands could skip DM-only and allowFrom policy
GHSA-xr4f-mjxj-w6w5High· 8.3OpenClaw: Non-owner chat senders could issue device-pairing bootstrap codes