OpenClaw: Matrix Verification Notices Bypass Matrix DM Policy and Reply to Unpaired DM Peers
Moderate severity
GitHub Reviewed
Published
Mar 26, 2026
in
openclaw/openclaw
•
Updated Mar 27, 2026
Description
Published to the GitHub Advisory Database
Mar 27, 2026
Reviewed
Mar 27, 2026
Last updated
Mar 27, 2026
Summary
Matrix Verification Notices Bypass Matrix DM Policy and Reply to Unpaired DM Peers
Affected Packages / Versions
openclaw<= 2026.3.242026.3.252026.3.24Details
Matrix verification notices previously bypassed DM access checks and could reply to peers that were unpaired or otherwise outside the allowed DM policy. Commit
2383daf5c4a4e08d9553e0e949552ad755ef9ec2gates verification notices on DM access before sending.Verified vulnerable on tag
v2026.3.24and fixed onmainby commit2383daf5c4a4e08d9553e0e949552ad755ef9ec2.Fix Commit(s)
2383daf5c4a4e08d9553e0e949552ad755ef9ec2References