GHSA-g7fw-3gjp-g5hf: Medium severity npm/@openclaw/googlechat vulnerability

Published Oct 5, 2026
·
Updated

Summary

Channel read actions could skip target allowlists. In affected versions, explicit read targets in Microsoft Teams, Feishu, Matrix, and Google Chat could reach channels or rooms outside the configured read policy.

This advisory is scoped to caller-supplied targets for message, reaction, pin, member, and related metadata reads in the named plugins. It does not change OpenClaw's trusted-operator model or create per-user isolation within one Gateway.

Impact

A lower-trust sender or steered agent with access to a channel read action could retrieve content or metadata from a target excluded by the operator's channel allowlist. Practical impact depends on the bot account's platform permissions.

Patched Versions

The first stable patched version is 2026.8.1.

Mitigations

upgrade each affected channel plugin to 2026.8.1 or later. Before upgrading, disable explicit-target read actions or limit the connected bot account to allowed channels at the platform level.

Affected Software

4 affected componentsFixes available
npm/@openclaw/googlechat<2026.8.1
2026.8.1
npm/@openclaw/matrix<2026.8.1
2026.8.1
npm/@openclaw/feishu<2026.8.1
2026.8.1
npm/@openclaw/msteams<2026.8.1
2026.8.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@openclaw/googlechat to a version that resolves this vulnerability.

    Fixed in 2026.8.1
  2. Upgrade

    Upgrade npm/@openclaw/matrix to a version that resolves this vulnerability.

    Fixed in 2026.8.1
  3. Upgrade

    Upgrade npm/@openclaw/feishu to a version that resolves this vulnerability.

    Fixed in 2026.8.1
  4. Upgrade

    Upgrade npm/@openclaw/msteams to a version that resolves this vulnerability.

    Fixed in 2026.8.1
  5. Upgrade

    Upgrade Microsoft Teams channel plugin to a version that resolves this vulnerability.

    Fixed in 2026.8.1
  6. Upgrade

    Upgrade Feishu channel plugin to a version that resolves this vulnerability.

    Fixed in 2026.8.1
  7. Upgrade

    Upgrade Matrix channel plugin to a version that resolves this vulnerability.

    Fixed in 2026.8.1
  8. Upgrade

    Upgrade Google Chat channel plugin to a version that resolves this vulnerability.

    Fixed in 2026.8.1
  9. Configuration

    Disable explicit-target read actions before upgrading.

    OpenClaw channel read actions explicit-target read actions = disabled
  10. Compensating control

    Limit the connected bot account to allowed channels at the platform level.

Event History

Oct 5, 2026
Advisory Published
via GitHub·11:27 PM
Data Sourced
via GitHub·11:27 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Deployments using the Microsoft Teams, Feishu, Matrix, or Google Chat channel plugins are affected when callers can supply explicit targets to channel read actions. Exposure is limited by the connected bot account's permissions on the relevant platform.

2

What does an attacker need to exploit it?

A lower-trust sender or a steered agent needs access to a channel read action and must be able to provide an explicit channel or room target. They can then request message, reaction, pin, member, or related metadata reads for targets outside the operator's configured channel allowlist.

3

Are channel allowlists sufficient protection before patching?

No. In affected versions, explicit read targets can bypass the configured read-policy allowlist. If upgrading is delayed, disable explicit-target read actions or restrict the bot account at the platform level so it can access only approved channels.

4

What version contains the fix?

The first stable patched version is 2026.8.1. Upgrade each affected channel plugin to 2026.8.1 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203