{"id":"GHSA-2ch6-x3g4-7759","aliases":[],"url":"https://o3.security/vulnerability/GHSA-2ch6-x3g4-7759","summary":"OpenClaw's commands.allowFrom sender authorization accepted conversation identifiers via ctx.From","details":"### Summary\n`commands.allowFrom` is documented as a sender authorization allowlist for commands/directives, but command authorization could include `ctx.From` (conversation identity) as a sender candidate.\n\nWhen `commands.allowFrom` contained conversation-like identifiers (for example Discord `channel:<id>` or WhatsApp group JIDs), command/directive authorization could be granted to participants in that conversation instead of only the intended sender identity.\n\n### Affected Packages / Versions\n- Package: `openclaw` (npm)\n- Affected versions: `<= 2026.2.22-2`\n- Patched version: `2026.2.23` (released)\n\n### Details\nRoot cause: `resolveSenderCandidates()` in `src/auto-reply/command-auth.ts` always included `ctx.From` in candidate evaluation used by `commands.allowFrom` authorization checks.\n\n`ctx.From` is sender-like in some direct-message contexts, but conversation-like in channel/group/thread contexts. This mixed principal handling allowed conversation identifiers to satisfy sender-only authorization.\n\n### Impact\nIn affected versions, command/directive authorization could become broader than intended when operators configured `commands.allowFrom` with conversation identifiers, allowing unintended users in that conversation to run command-only/directive-only flows.\n\n### Fix\nMain branch now treats `commands.allowFrom` as sender-only:\n- `ctx.From` is no longer included as a general sender candidate.\n- `ctx.From` is only used as fallback when sender fields are absent and the value is not conversation-shaped.\n- Regression tests were added for conversation-id denial and direct-message fallback preservation.\n\n### Fix Commit(s)\n- `08e2aa44e78a9c946d97bea62304e6f533b8fa8e`\n\n### Release Process Note\n`patched_versions` is pre-set to the released version (`2026.2.23`). This advisory now reflects released fix version `2026.2.23`.\n\nOpenClaw thanks @jiseoung for reporting.","published":"2026-03-03T23:19:46Z","modified":"2026-03-04T15:09:59.987542Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"openclaw","fixedVersion":"2026.2.23"}],"fix":{"url":"https://github.com/openclaw/openclaw/commit/08e2aa44e78a9c946d97bea62304e6f533b8fa8e","label":"openclaw/openclaw@08e2aa4"},"references":[{"type":"WEB","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-2ch6-x3g4-7759"},{"type":"WEB","url":"https://github.com/openclaw/openclaw/commit/08e2aa44e78a9c946d97bea62304e6f533b8fa8e"},{"type":"PACKAGE","url":"https://github.com/openclaw/openclaw"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-03-04T15:09:59.987542Z"}}