{"id":"GHSA-j26j-7qc4-3mrf","summary":"OpenClaw: MS Teams fileConsent/invoke missing conversation binding allowed cross-conversation pending-upload consumption","details":"### Summary\nIn `openclaw` MS Teams file-consent flow, pending uploads were authorized by `uploadId` alone. `fileConsent/invoke` did not verify the invoke conversation against the conversation that created the pending upload.\n\n### Impact\nAn attacker who obtained a valid `uploadId` within TTL could trigger cross-conversation upload completion (accept path) or cancel a victim pending upload (decline path).\n\n### Technical Details\n- Pending uploads stored `conversationId`, but invoke handling consumed by `uploadId` only.\n- The invoke path did not enforce conversation binding before `uploadToConsentUrl(...)` and pending-upload removal.\n- Fix binds accept/decline handling to normalized conversation id match before consuming pending upload state.\n\n### Affected Packages / Versions\n- Package: `openclaw` (npm)\n- Latest published npm version (as of February 26, 2026): `2026.2.24`\n- Vulnerable range: `\u003c= 2026.2.24`\n- Patched in release: `2026.2.25`\n\n### Remediation\nUpgrade to `openclaw` `2026.2.25` (or later) once published.\n\n### Fix Commit(s)\n- `347f7b9550064f5f5b33c6e07f64e85b9657b6f1`\n\n### Release Process Note\n`patched_versions` is pre-set to the release (`2026.2.25`). Advisory published with npm release `2026.2.25`.\n\nOpenClaw thanks @tdjackey for reporting.","modified":"2026-03-04T15:15:13.314096Z","published":"2026-03-03T21:36:49Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-03-03T21:36:49Z","nvd_published_at":null,"cwe_ids":["CWE-639","CWE-862"]},"references":[{"type":"WEB","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-j26j-7qc4-3mrf"},{"type":"WEB","url":"https://github.com/openclaw/openclaw/commit/347f7b9550064f5f5b33c6e07f64e85b9657b6f1"},{"type":"PACKAGE","url":"https://github.com/openclaw/openclaw"}],"affected":[{"package":{"name":"openclaw","ecosystem":"npm","purl":"pkg:npm/openclaw"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2026.2.25"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-j26j-7qc4-3mrf/GHSA-j26j-7qc4-3mrf.json","last_known_affected_version_range":"\u003c= 2026.2.24"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}