GHSA-jv6r-27ww-4gw4: OpenClaw DM pairing-store identities could satisfy group allowlist authorization
DM pairing-store identities were incorrectly eligible for group allowlist authorization checks, enabling cross-context authorization in group message paths.
References
Code Behaviors & Features
Detect and mitigate GHSA-jv6r-27ww-4gw4 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →