OpenClaw: Mattermost callback dispatch allowed non-allowlisted sender actions
Moderate severity
GitHub Reviewed
Published
Mar 24, 2026
in
openclaw/openclaw
•
Updated Mar 26, 2026
Description
Published to the GitHub Advisory Database
Mar 26, 2026
Reviewed
Mar 26, 2026
Last updated
Mar 26, 2026
Summary
Mattermost interactive callback dispatch could run action handlers before normal sender authorization checks completed.
Affected Packages / Versions
openclaw(npm)v2026.3.23-2(630f1479c44f78484dfa21bb407cbe6f171dac87)2026.3.23-2Fix Commit(s)
a47722de7e3c9cbda8d5512747ca7e3bb8f6ee66Release Status
The fix shipped in
v2026.3.22and remains present inv2026.3.23andv2026.3.23-2.Code-Level Confirmation
OpenClaw thanks @zpbrent for reporting.
References