high · CVSS v3 6.5 · CVSS v4 7.1 · EPSS 0.00209
CVE-2026-100582
OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8…
Description
OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8.1 do not enforce the configured channel read allowlist for caller-supplied explicit read targets in message, reaction, pin, member, and related metadata read actions. A lower-trust sender or a steered agent with access to a channel read action can therefore retrieve content or metadata from channels or rooms excluded by the operator's read policy; the practical impact depends on the permissions held by the connected bot account. The issue is fixed in 2026.8.1.
Scores
- Severity
- high
- CVSS v2
- 6.8
- CVSS v3
- 6.5
- CVSS v4
- 7.1
- EPSS
- 0.00209