🛡️ CVE Monitor
Dịch vụ / phần mềm liên quan: Node.js / npm

Mô tả

OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name portion — when deriving the OpenClaw authorization identity. As a result, distinct authenticated Matrix accounts can normalize to the same authorization identity. A Matrix participant controlling a colliding account identifier (a protocol-valid identifier that differs from the configured one only by characters OpenClaw case/Unicode folds; display-name matching is not required) can inherit allowlist, owner-command, exec-approval, or plugin-approval authority configured for another account. The issue is fixed in 2026.8.1.

Chi tiết

Trạng tháiDeferred
Điểm CVSS7.5 (v3.1)
Vector CVSSCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Ngày công bố10:16 26/09/2026
Ngày cập nhật22:23 28/09/2026
Nguồn dữ liệunvd

CWE

  • CWE-178

Sản phẩm bị ảnh hưởng

Nguồn dữ liệu chưa cung cấp thông tin sản phẩm chi tiết.

Tài liệu tham khảo

Lịch sử thay đổi

Thời gianLoạiTrườngGiá trị cũGiá trị mới
22:27 28/09/2026 CREATED cve HIGH

Tất cả thời gian trên trang này hiển thị theo giờ Việt Nam (GMT+7).