GHSA-g7fw-3gjp-g5hf: Medium severity npm/@openclaw/googlechat vulnerability
Summary
Channel read actions could skip target allowlists. In affected versions, explicit read targets in Microsoft Teams, Feishu, Matrix, and Google Chat could reach channels or rooms outside the configured read policy.
This advisory is scoped to caller-supplied targets for message, reaction, pin, member, and related metadata reads in the named plugins. It does not change OpenClaw's trusted-operator model or create per-user isolation within one Gateway.
Impact
A lower-trust sender or steered agent with access to a channel read action could retrieve content or metadata from a target excluded by the operator's channel allowlist. Practical impact depends on the bot account's platform permissions.
Patched Versions
The first stable patched version is 2026.8.1.
Mitigations
upgrade each affected channel plugin to 2026.8.1 or later. Before upgrading, disable explicit-target read actions or limit the connected bot account to allowed channels at the platform level.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@openclaw/googlechatto a version that resolves this vulnerability.Fixed in 2026.8.1 - Upgrade
Upgrade
npm/@openclaw/matrixto a version that resolves this vulnerability.Fixed in 2026.8.1 - Upgrade
Upgrade
npm/@openclaw/feishuto a version that resolves this vulnerability.Fixed in 2026.8.1 - Upgrade
Upgrade
npm/@openclaw/msteamsto a version that resolves this vulnerability.Fixed in 2026.8.1 - Upgrade
Upgrade
Microsoft Teams channel pluginto a version that resolves this vulnerability.Fixed in 2026.8.1 - Upgrade
Upgrade
Feishu channel pluginto a version that resolves this vulnerability.Fixed in 2026.8.1 - Upgrade
Upgrade
Matrix channel pluginto a version that resolves this vulnerability.Fixed in 2026.8.1 - Upgrade
Upgrade
Google Chat channel pluginto a version that resolves this vulnerability.Fixed in 2026.8.1 - Configuration
Disable explicit-target read actions before upgrading.
OpenClaw channel read actions explicit-target read actions = disabled - Compensating control
Limit the connected bot account to allowed channels at the platform level.
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments using the Microsoft Teams, Feishu, Matrix, or Google Chat channel plugins are affected when callers can supply explicit targets to channel read actions. Exposure is limited by the connected bot account's permissions on the relevant platform.
What does an attacker need to exploit it?
A lower-trust sender or a steered agent needs access to a channel read action and must be able to provide an explicit channel or room target. They can then request message, reaction, pin, member, or related metadata reads for targets outside the operator's configured channel allowlist.
Are channel allowlists sufficient protection before patching?
No. In affected versions, explicit read targets can bypass the configured read-policy allowlist. If upgrading is delayed, disable explicit-target read actions or restrict the bot account at the platform level so it can access only approved channels.
What version contains the fix?
The first stable patched version is 2026.8.1. Upgrade each affected channel plugin to 2026.8.1 or later.