https://advisories.gitlab.com/npm/openclaw/GHSA-354r-7mfh-7rh2/
OpenClaw: Discord DM reaction ingress missed dmPolicy/allowFrom checks in restricted setups |...
https://advisories.gitlab.com/npm/openclaw/CVE-2026-32021/
OpenClaw has a Feishu allowFrom authorization bypass via display-name collision | GitLab Advisory...
CVE-2026-32021 OpenClaw has a Feishu allowFrom authorization bypass via display-name collision: Feishu allowlist authorization could be bypassed by...
https://advisories.gitlab.com/npm/openclaw/GHSA-f693-58pc-2gfr/
OpenClaw: Telegram legacy allowFrom migration fans default-account trust into all named accounts |...
GHSA-f693-58pc-2gfr OpenClaw: Telegram legacy allowFrom migration fans default-account trust into all named accounts: Telegram legacy allowFrom migration fans...
https://advisories.gitlab.com/npm/openclaw/CVE-2026-22170/
OpenClaw: BlueBubbles (optional plugin) pairing/allowlist mismatch when allowFrom is empty | GitLab...
CVE-2026-22170 OpenClaw: BlueBubbles (optional plugin) pairing/allowlist mismatch when allowFrom is empty: BlueBubbles is an optional OpenClaw channel plugin....
https://advisories.gitlab.com/npm/openclaw/CVE-2026-28448/
OpenClaw Twitch allowFrom is not enforced in optional plugin, unauthorized chat users can trigger...
CVE-2026-28448 OpenClaw Twitch allowFrom is not enforced in optional plugin, unauthorized chat users can trigger agent pipeline: In the optional Twitch channel...